AD-A258  026 


September  1992/Number  4-92 


security 


DTI 

ELECTS 
NOV  2  5 1992 


What  is  the  Threat  and  the  New  Strategy?  . 1 

National  Industrial  Security  Program . 7 

Defense  Treaty  Inspection  Readiness  Program ...  21 

Security  Penguin  Contest . 23 

Security  Programs  Improvement  Network . 29 


•.  iW:  uii-i  :,yj  oppTOVSd 

;  .  i  a  aj  tl  eoIc;  ite 


bu  et  n 


Department  of  Defense  Security  Institute,  Richmond,  Virginia 


/ » 

I’  ^  0 


awareness 


security  awareness  bulletin 

Approved  for  open  publication  Unlimited  reproduction  authorized 

Director  Editor 

Department  of  Defense  Security  Institute  Lynn  Fischer 

R.  Everett  Gravelle 

Staff  Writer 

Tracy  Gulledge 

The  Security  Awareness  Bulletin  \s  produced  by  the  Department  of  Defense  Security  Institute,  Educa¬ 
tional  Programs  Department,  do  Defense  General  Supply  Center,  Richmond  Virginia  23297-5091 ;  (804) 
279-3824/4223,  DSN  695-3824/4223.  Primary  distribution  is  to  DoD  components  and  contractors 
cleared  for  classified  access  under  the  Defense  Industrial  Security  Program  and  Special  Access 
Programs.  Our  purpose  is  to  promote  security  awareness  and  compliance  with  security  procedures 
through  dissemination  of  information  to  security  trainers  regarding  current  security  and  counterintel¬ 
ligence  developments,  training  aids,  and  educational  methods  as  well  as  through  distribution  of  textual 
material  for  direct  training  application. 

Administrative  inquiries,  new  distribution,  address  changes:  please  refer  as  follows: 

Army  activities:  HQ  DA  (DAMI-CIS),  Washington.  DC  20310,  (202)  695-8920,  DSN  225-8920; 

POC  Jim  McElroy 

Navy  &  Marine  Corps:  Security  Policy  Div  (OP-09N),  Washington,  DC  20350 
(202)  433-8855.  DSN  288-8855;  POC  Sue  Jones 

Air  Force;  Headquarters  AFSPA/SPGB,  Kirtland  AFB,  NM  87117,  DSN  246-4787;  POC  MSgt.  Mike  Trammel 

DIS  activities:  HQ  DISA/0953. 1900  Half  St  SW,  Washington  DC  20324-1700 

DISP  contractors:  Cognizant  Security  Office 

Other  government  agencies;  Headquarters  security  education  office 


What  is  the  Threat  and  the  New  Strategy? 


bjf  Daoid  G.  Major 

Special  Assistant  to  the  Assistant  Director  in  Charge, 
Intelligence  Division,  Federal  Bureau  of  Investigation 

The  collapse  of  international  communism,  the 
democratization  of  Eastern  Europe,  and  the  dismem¬ 
berment  of  d\e  former  Soviet  Union  have  forced  us 
to  dramatically  reinterpret  the  international  intel¬ 
ligence  threat  to  the  United  States.  Those  who  can 
speak  for  the  intelligence  community  have  been  un- 
derstandably  cautious  about  making 
authoritative  pronotmcements  about  who  is 
threatening  us  militarily,  economically,  and 
politically.  Things  have  been  moving  so  fast 
that  anything  but  the  most  general  inter¬ 
pretation  of  events  is  soon  out  of  date.  How¬ 
ever,  there  has  been  an  on-going  interagency 
effort  to  assess  what  changes  have  taken 
pbce  in  the  international  intelligence  arena 
and  what  future  developments  we  are  likely 
to  see. 

A  truly  international  threat 

While  the  line  between  friendly  nations 
and  potential  adversaries  has  blurred,  be 
aware  that  of  the  ITQ-plus  countries  in  the 
world,  over  50%  of  them  conduct  some  level 
of  intelligence  collection  operations  against 
the  U.S.  During  the  Cold  War,  the  US 
counterintelligence  commuiuty  focused  on 
about  11%  of  these  countries,  and  we 
referred  to  them  as  the  hostile  intelligence  threat. 

Historically  we  were  primarily  concerned  with 
the  Soviet  intelligence  services— the  KGB  (Commit¬ 
tee  for  State  Security),  the  GRU  (the  Chief  Intel¬ 
ligence  Directorate  of  the  Ministry  of  Defense),  and 
the  assortment  of  satellite  services  from  Bloc  nations 
which,  often  with  greater  success,  launched  sophis¬ 
ticated  huiium  intelligence  (HUMINT)  operations 
against  U.S.  dtizeiw  at  home  and  abroad.  The  big 
question  is,  where  has  this  monolithic  intelligence 


empire  gone?  The  former  Soviet  services  are  tmder- 
going  rapid  evolution  in  terms  of  function  and 
geographic  scope.  They  are,  however,  still  alive  and 
welL  The  inffastructure  of  the  KGB  remains  and  still 
has  the  same  mission  for  external  collection  ac¬ 
tivities. 

Demise  of  the  old  KGB? 

The  former  1st  Chief  Directorate  of  the  KGB  is 
now  the  Russian  Foreign  Intelligence  Service 
(SVRR).  The  old  KGB  was  a  big  loser  in  foe 
coup  attempt,  but  the  axes  fell  on  top 
management  The  middle  management  and 
"worker  bee"  inffastructure  is  still  intact. 
They  have  not  stopped  or  even  slowed  their 
operations.  The  Russians  are  still  meeting 
and  pa}dng  their  agents.  We  believe  the 
Russians  are  being  more  cautious  in  their 
operations  to  avoid  potential  political  em¬ 
barrassment,  and  therefore  stress  quality  of 
collection  rather  than  quantity. 

The  KGB  SIGINT  (and  other  tedmical 
collection)  apparatus  simply  changed  its 
name  and  has  continued  its  operation  with 
no  observable  changes  in  level  or  mefoods. 
The  GRU  (military  intelligence)  is  still  very 
much  in  foe  collection  business.  There  have 
been  no  indications  that  their  efforts  have 
decreased  in  intensity.  They  are  still  accept¬ 
ing  volimteers  and  meeting  with  agents 
worldwide. 

Former  satellite  intelligence  services 

Significant  changes,  however,  have  occurred  in 
Eastern  Europw.  Five  countries  formerly  in  foe  Soviet 
Bloc  have  shut  down  their  collection  activities 
against  foe  U.S.; 

•  East  Gemumy  no  longer  exists.  Revelations 
horn  foe  intelligence  files  of  foe  former  German 
Democratic  Republic  show  that  East  German  in- 


Over  50%  of 
the  170 
countries  In 
the  world 
conduct 
Intelllgehce 
collection 
opei^ions 
against  the 
US. 


77/0  Infrastructure  of  the  KGB  remains  and  still  has  the  same  mission  for  external 

collection  activities. 


Niinb«r4-93 


1 


Security  Awaretieu  Bulletin 


telligence  was  very  successful.  Their  success  is 
not  surprising  when  you  consider  that  they  had 
more  than  80,000  professional  intelligence  of¬ 
ficers  and  almost  1  million  non-professional 
agents  and  informants  in  a  nation  of  18  million 
individuals. 

•  Poland  is  no  longer  running  collection  opera¬ 
tions  against  the  U.S.  and  has  withdrawn  intel¬ 
ligence  officers  from  North  America. 

•  Hungary  has  terminated  operations  against  us. 

•  Czechoslovakia  fired  and  replaced  its  entire  intel¬ 
ligence  apparatus.  Their  operations  against  the 
United  States  have  terminated. 

•  Bulgaria  has  also  stopped  its  collection  efforts 
targeting  the  United  States. 

The  much-publicized  reassignment  of  300  FBI 
agents  from  counterintelligence  to  other  missions 
was  done  in  response  to  the  disappearance  of  the 
threat  from  the  five  countries  listed  above.  It  indi¬ 
cates  that  we  do  not  currently  face  an  intelligence 
threat  from  these  countries  and  nothing  more. 

An  exception  to  the  general  trend  of  other 
Central  European  countries  is  Rumania,  whose  in¬ 
tentions  regarding  collecting  against  the  U.S.  are  un¬ 
clear.  There  are  some  indications  that  they  may  be 
increasing  their  efforts,  and  are  therefore  still  con¬ 
sidered  a  threat. 

Shifting  our  attention  to  the  non-traditionai  threat 

The  changes  in  the  threat  from  Eastern  Europe 
and  the  old  Soviet  camp  have  allowed  us  to  also  focus 
our  attention  on  the  "non-traditional  threat" — the 
threat  from  the  remaining  "50%"  that  actively  target 
the  United  States.  This  is  actually  not  a  new  threat, 
but  a  new  recognition  or  acceptance  of  what  the 
intelligence  community  has  been  saying  for  some 
time:  there  may  be  friendly  nations,  but  few  friendly 
foreign  intelligence  services. 

What  we  are  calling  the  non-traditional  threat 
includes  many  members  of  the  Third  World  which 
have  targeted  U.S.  citizens  working  overseas.  The 
most  well-known  example  of  this  is  Ghana  which 


successfully  coopted  a  U.S.  diplomatic  employee 
several  years  ago. 

ITiere  are  also  nations  which  are  interested  in 
nuclear,  chemical,  or  biological  proliferation.  Iraq 
and  other  countries  use  their  intelligence  services  to 
assist  in  the  development  of  these  capabilities.  This 
category  includes  our  allies  which  do  not  have 
benign  intelligence  services  with  regard  to  our  com¬ 
panies  and  technology. 

Domestic  volunteers:  a  continuing  problem 

One  thing  to  keep  in  mind  is  that  the  changes  in 
international  politics  have  nothing  to  do  with  the 
motivations  of  the  "volunteer  agent."  These  include 
people  (U.S.  citizens)  like  John  Walker,  Ronald  Pel- 
ton,  and  more  recently,  Jeffrey  Carney.  Since  these 
individuals  appear  to  be  motivated  by  many  factors 
including  a  need  for  money,  revenge,  or  by  more 
deep-seated  psychological  causes,  the  collapse  of  in¬ 
ternational  communism  has  little  or  no  significance 
to  them.  People  intent  on  betrayal  of  a  trust,  for 
whatever  reason,  will  look  for  other  customers. 
Needless  to  say,  a  top  priority  in  our  counterintel¬ 
ligence  strategy  is  to  identify  and  deal  with  these 
"volunteers"  before  they  can  damage  national  inter¬ 
ests. 

A  new  strategy  for  combatting  the  threat 

Because  of  these  dramatic  changes  in  the  natuio 
of  the  threat,  the  FBI  has  adopted  a  new  counterin¬ 
telligence  strategy  which  has  been  in  effect  since 
February  1st,  1992.  This  strategy  is  based  on  a  num¬ 
ber  of  assumptions.  First,  the  number  of  foreign 
intelligence  services  targeting  U.S.  information  is  not 
likely  to  decrease.  Second,  national  security  and 
economic  strength  are  indivisible,  and  as  a  corollary, 
economic  and  military  strength  depend  on  both  our 
intelligence  collection  efforts  and  effective  counterin¬ 
telligence.  Third,  our  counterintelligence  organiza¬ 
tions  must  be  responsive  to  change  and  serve  as  an 
alarm  bell  to  the  larger  community. 

We  cannot  overlook  a  couple  of  facts  of  life  that 
have  made  our  job  more  difficult  and  have  led  us  to 
reexamine  the  way  in  which  we  allocate  limited 
resources  to  meet  the  new  threat:  (a)  the  massive 
influx  of  foreign  nationals  from  the  former  Soviet 


Thei^  may  be  friendly  nations,  but  few  friendly  foreign  intelligence  services. 


Security  Awareness  Bulletin 


2 


Number  4-92 


The  number  of  arrests  for  espionage  is  not  a  refiection  of  the  ievei  of  foreign  intei- 
iigence  coiiection  activities  directed  at  U.S.  interests. 


Union  and  Bloc  nations — both  visitors  and  commer¬ 
cial  representatives — to  the  United  States,  and  (b)  the 
corresponding  increase  of  U.S.  citizens  travelling  to 
formerly  restricted  areas  for  business  and  pleasure. 

The  National  Security  Threat  List 

Consequently,  no  longer  will  the  Bureau  focus 
on  a  set  of  “hostile  countries."  Instead  of  a  "country 
list,"  there  will  be  a  two-part  "National  Security 
Threat  List"  (the  NSTL)  which  will  be  reviewed  and 
updated  annually. 

U.S.  intelligence  agencies  will  continue  to  iden¬ 
tify  countries  or  other  political  entities  which  can  be 
expected  to  mount  collection  operations  against  us. 
These  will  be  reviewed  by  the  FBI  and  Department 
of  Justice  in  cooperation  with  the  State  Department. 
Inclusion  on  the  list  will  be  based  on  the  observed 
level  of  intelligence  activity;  the  nature  of  the  infor¬ 
mation  being  targeted;  the  capability  of  that  country 
or  entity  to  conduct  intelligence  activities;  and  our 
political,  military,  and  economic  alignment  with  that 
country.  The  nations  or  poliHcal  entities  identified 
as  threats  under  the  NSTL  will  be  classified.  This 
part  of  the  list  will  not  be  disseminated  outside  of  the 
FBI  since  it  is  an  internal  mechanism  for  directing  the 
Bureau's  foreign  counterintelligence  operations. 
However,  defense  contractors  and  Federal  agencies 
will  continue  to  be  alerted  about  specific  threat  situa¬ 
tions  through  the  DECA  program  (Development  of 
Espionage  and  Counterintelligence  Awareness)  and 
other  special  briefings. 

The  second  part  of  the  list  identifies  issues  critical 
to  our  national  security.  Some  of  these  issues  in¬ 
clude:  national  defense  information,  critical  technol¬ 
ogy,  economic  proprietary  information  which  affects 
our  industrial  base,  and  foreign  policy  information. 
Some  of  these  categories  of  information  clearly  fall 
outside  of  the  realm  of  traditionally  classified  infor¬ 


mation.  (Editor's  note:  see  the  chart  that  follows.) 
The  objectives  of  the  NSTL  will  be  to  identify  and 
neutralize  the  foreign  intelligence  threat,  focus  on  the 
collector  and  its  targets,  identify  the  nation's  most 
precious  secrets,  and  focus  and  direct  Cl  investiga¬ 
tions  against  intelligence  activities. 

I  wish  to  stress  that  the  prosecution  of  "spies", 
while  paramount  in  our  counterintelligence  pro¬ 
gram,  is  not  the  only  possible  response  to  the  dis¬ 
covery  and  interdiction  of  intelligence  collection 
efforts.  In  fact,  fewer  than  ten  percent  of  the  clandes¬ 
tine  agents  we  identify  are  ever  prosecuted.  Among 
the  numerous  reasons  why  agents  might  not  be  ar¬ 
rested  or  prosecuted  are:  It  may  be  to  our  advantage 
to  (a)  exploit  specific  operations  to  learn  the  methods, 
techniques,  and  structures  of  intelligence  services  or 
(b)  to  mount  a  double-agent  operation  against  the 
source.  What  is  important  to  recognize  is  that  the 
number  of  arrests  for  espionage  is  uof  a  reflection  of 
the  level  of  foreign  intelligence  collection  activities 
directed  at  U.S.  interests.  Each  year  we  arrest  and 
prosecute  only  a  handful  of  those  individuals  in¬ 
volved  in  espionage  as  compared  to  the  hundreds  of 
espionage  operations  which  we  actually  neutralize. 


Bottom  Line  for  the  NSTL 

An  offensive  Cl  response  will  be  d  irected  against 
any  foreign  power  conducting  intelligence  activities 
against  the  U.S.  regardless  of  our  political,  military, 
or  economic  alignment  with  that  country.  Our 
strategy  will  be  flexible,  sensitive,  and  responsive  not 
only  to  rapid  changes  in  the  geopolitical  world  stage, 
but  also  to  the  growth  of  new  technologies  and  to 
intelligence  operations  launched  by  friend  and  foe 
alike  which  target  U.S.  interests. 


Oist 


'cc'cs 

r 

Number  4-92 


3 


Security  Awareness  Bulletin 


National  Security  Threat  List 
Issue  Threats 


The  following  categories  of  activities  designated  as  issue  threats  under  the  NSTL  as 

of  December  30, 1991: 

•  Foreign  intelligence  activities  directed  at  United  States  critical 
technologies  as  identified  by  the  National  Critical  Technologies  PaneP 

•  Foreign  intelligence  activities  directed  at  the  collection  of  United  States 
industrial  proprietary  economic  information  and  technology,  the  loss  of 
which  would  undermine  the  U.S.  strategic  industrial  position 

•  Clandestine  foreign  intelligence  activity  in  the  United  States 

•  Foreign  intelligence  activities  directed  at  the  collection  of  information 
relating  to  defense  establishments  and  related  activities  of  national 
preparedness 

•  Foreign  intelligence  activities  involved  in  the  proliferation  of  special 
weapons  of  mass  destruction  or  delivery  systems  of  weapons  of  mass 
destruction 

•  Foreign  intelligence  activities  involving  the  targeting  of  U.S.  intelligence 
and  foreign  affairs  information  and  U.S.  government  officials 

•  Foreign  intelligence  activities  involving  active  measures^ 


*  The  National  Critical  Technologies  Panel,  established  in  FY  1990,  is  charged  with  identifying  up  to  30  technologies  essential  for  our  long-term 
national  security  and  economic  prosperity.  It  consists  of  13  members  ivith  expertise  in  the  fields  of  science  and  engineering  chosen  from  the  Federal 
government  and  the  private  sector. 


^  propaganda  and  disinformation  programs  by  foreign  intelligence  services  to  discredit  the  United  States 


Number  4-92 


4 


Security  Awareness  Bulletin 


Evolution  of  the  Russian  Intelligence  Services 


M8RF’ 

Russia’^  Federal 
i,li::;s;:y'  far  Security 
caa^dicedMSBand  AFB 

es:  .3-  ’932 
Hcaa  V  -‘z-  Ba-a-”'  r>c.' 
bro'sr.a  Ee2;3as'':s:  Rsssysiroy 


MBVD* 

Ministry  Of  Security  and 
Internal  Affairs 
propoMdlSOecISSI 
r«jected14Jan1992 
oomUned;  USSR  MVD,  RSFSR  MVD 
MSB»)dAFB 
Head  Viktor  Barannikov 
*Mini«iBntvo  Bezopasnosti 
Vhutrannykh  Del 


t 


AFB* 

Agency  for  Federal  Security 
an  Nov  1991 
Head  Viktor  tvamnko 


SVRR* 

Russian  Foreign 
Intelligence  Service 
es;  Dec  199! 

Head  Ye.geciy  Pr:rakov 

•Sluzi'ba  Vr;esr'''oy  Rarjedk.  Rossiya 


Commonwealth  of 
Independent  States' 
Border  Guards* 
esr  Dec  ’99’ 

Head  I:  ya  KaC'' 

■Sacr^z.r-esr.'o  Meza:  s 
Gosada'Slv  Po9ra'‘iCcryye  Vc,S'3 


*Agar«No  FMeratnoy  BezopaanoaS 


RSFSR  KGB' 
aatMiyigpi 
Haad:  Viktor  Ivanenko 
ap.  May  1991 


USSR  KGB 
Head;  Vadim  BakaUn 
ap.  Aug  1991 


+  MinMy  was  eraetad  by  a  decraa  from  Russian  President  Yelt- 
ain  and  la  awaiting  approval  from  the  Russian  partiamant. 


USSR  KGB 
Haad;  Vladimir  Kryuchkov 
ap.  May  1968 


'  Ruialan  Soviet  Federal  Socialist  Republic 


March  1992 


Number  4-92 


5 


Security  Aioareness  Bulletin 


COURSE  TITLE 

Personnel  Security  Interview  Course 
(5220.15) 

LOCATION 

Department  of  Defense  Security  Institute 
c/ o  Defense  General  Supply  Center 
Richmond,  Virginia  23297-5091 

LENGTH 

Three  and  One-Half  Days 
PURPOSE 

The  Personnel  Security  Interview  Course  is  designed  to  train  and  educate  DoD  personnel  who  conduct 
interviews  of  individuals  who  perform  sensitive  duties  or  work  in  a  security  environment. 

SCOPE 

The  Personnel  Security  Interview  Course  offers  training  in  how  to  properly  conduct  a  subject  interview.  Lessons 
address  the  purpose  of  the  interview;  how  to  prepare  for  the  interview;  the  procedures  for  controlling  and 
conducting  interviews;  appropriate  and  inappropriate  areas  of  questioning;  effective  listening;  and  how  to 
identify,  follow  up  and  resolve  issues  raised  by  the  interview.  The  Personnel  Security  Interview  Course  uses 
extensive  practical  exercises,  providing  students  with  several  opportunities  to  apply  the  knowledge  and 
skills  taught.  Some  outside-of-class  preparations  and  problem-solving  assignments  are  required. 

PREREQUISITES 

This  course  is  for  DoD  civilian,  military  or  contractor  personnel  who  conduct  personnel  security  interviews. 
Personnel  from  other  federal  agencies  are  eligible  to  attend  on  a  space  available  basis. 

ACADEMIC  REQUIREMENTS 

Regular  attendance  at  and  participation  in  all  sessions  is  required  for  a  certificate  of  completion. 


Don't  confuse  this  course  with  the  Basic  Personnel  Security  Investigations  Course  (BPSIC).  If  your 
employee.s  conduct  personnel  security  investigations,  you  want  BPSIC.  But  if  they  conduct  pre-in vestiga- 
tive  interviews  to  screen  personnel,  or  post-adjudicative  interviews  to  resolve  issues,  the  Personnel  Security 
Interview  Course  is  for  you. 


TRAINING  FUNDS  A  PROBLEM? 

If  so,  it  might  make  sense  to  host  an  offering  of  the  Personnel  Security  Interview  Course  at  your  location  (even 
overseas).  If  you  provide  the  facilities,  your  only  cost  would  be  the  TDY  expenses  of  2-3  DoDSI  instructors. 
In  addition,  we  would  be  willing  to  tailor  the  course  content  and  practical  exercises  to  meet  your  specific 
needs  and  your  agency's  pnliries.  For  more  information,  call  DoDSI  at  DSN  695-4891  or  804-279-4891. 


Security  Awareness  Bulletin 


Number  4-92 


Origin  And  History  Of 
The  National  Industrial  Security  Program 


ByMejfturdAttdemm 
Deputy  Under  Secretary  cfDefenae 
(Security  Poticyl 


Background 

The  National  Industrial  Security  Program 
(NISP)  is  a  single,  coherent,  and  integrate  govern¬ 
ment  security  program  with  uniform,  consistent 
standards  and  procures  for  the  protection  of 
government  deified  information  held  by  in¬ 
dustry.  It  mandates  that  all  government  depart¬ 
ments  and  agencies  which  contract  with  private 
companies  to  perform  work  requiring  the  use  of 
government  classified  information  will  protect  that 
information  in  a  uniform  way  and  in  accordance 
with  a  single  government  regulation. 

Events  leading  to  creation  of  a  NISP  took  form 
as  identifiable  activities  in  the  early  1980's  when 
various  government  and  industry  security  officials 
began  to  express  concerns  about  the  process  and  ef¬ 
fectiveness  of  safeguarding  classified  information 
held  by  industry.  The  concerns  grew  out  of  the  in- 
creasL-.g  number  of  separate,  conflicting,  confusing 
and  sometimes  arcane  regulations  prepared  by 
each  government  deprutment  and  agency  or  the 
protection  of  the  same  kinds  of  mformation. 
Dociunentation  of  circumstances  began  to  emerge 
in  which  classified  iid'ormation  was  subjected  to  in¬ 
discriminate,  inconsistent,  repetitious,  unneces¬ 
sary,  and  even  unworkable,  security  procedures  at 
costs  not  commensurate  with  the  risk  of  com¬ 
promise.  Iitiormal  discussiorrs  of  the  evolution  of 
these  situations  among  industry  and  government 
officials  over  a  period  of  years  had  resulted  in  no 
significant  progress  toward  improvement. 

Because  of  the  predominance  of  the  Defense  In¬ 
dustrial  Security  Program  (DISP)  in  industrial  con¬ 
tracting  by  the  government,  the  Department  of 
Defense  (DoD)  was  clearly  responsible  for  many  of 
the  situations  and  actions  that  led  to  the  NISP  con- 
cqjt.  During  the  late  1970's  and  early  1980's  there 
began  to  emerge  a  specter  that  concerned  the  Direc¬ 
tor,  Defense  Investigative  Service  (DIS),  as  the  ad¬ 
ministrator  of  the  DISP.  His  concerns  centered 

TNa  aiticla  k  an  adfted  verston  of  Mr.  Anderson's  paper  *A  Prudent 
Approacti  to  Industrial  Security— The  National  Indusi^  Security  Pro- 
qmm.' 


aroimd  the  emergence  of  numerous  special  access 
progranns  (SAPs)  protecting  weapon  system  ac¬ 
quisition,  many  of  which  had  diverse  requirements 
and  were  "carved  out"  from  mspection  by  the  DIS. 
Some  of  these  SAPs  were  created  by  renegade  pro¬ 
gram  managers  who  believed  that  they  allowed 
more  efficient  operations.  In  fact,  they  imposed 
costly  requirements  on  the  contractors  involved 
and  hid  from  view  possible  security  irregularities 
that  would  have  been  disclosed  through  regular, 
impartial  inspections. 

In  all  fairness,  some  of  these  programs  that  con¬ 
trolled  advanced  technologies  used  to  produce 
modem,  sophisticated  weapon  systems  were  of 
benefit  to  the  government.  They  were  outnum¬ 
bered,  however,  by  those  of  questioiuible  value 
that  appeared  to  be  nothing  more  than  a  means  to 
circumvent  proper  itupections  and,  sometimes, 
proper  management. 


Special  access  programs  may  be  created 
only  by  designated  Agency  Heads  pursuant  to  Sec¬ 
tion  4.2  of  Executive  Order  12356,  "National 
Security  Information,”  Aprii  6, 1982. 

The  criteria  for  establishment  of  SAPs  are,  (a) 
normal  management  and  safeguarding  procedures 
do  not  limit  access  sufficiently  to  the  nation’s  most 
sensitive  lational  security  information,  and  (b)  the 
number  of  persons  with  access  is  limited  to  the 
minimum  number  necessaiy  to  meet  the  objectives 
of  providing  extra  protection  for  the  information. 

As  defined  by  DoD  Directive  0-5205.7,  "Special 
Access  Program  (SAP)  Policy,"  January  4, 1989,  a 
SAP  is,  “Under  the  authority  of  E.0. 12356 ...  and 
as  implemented  by  the  ISOO  Directive  No.  1 ...  any 
program  created  by  an  Agency  Head  whom  the 
President  has  designated  in  the  Federal  Register 
to  be  an  original  TOP  SECRET  classification 
authority  that  imposes  "need-to-know"  or  access 
controls  beyond  those  nomnally  required  by  DoD 
Regulations  for  access  to  CONFIDENTIAL, 
SECRET,  or  TOP  SECRET  information.*  Prior  to 
issuance  of  this  directive,  SAP  creation  and  over¬ 
sight  in  the  DoD  was  controlled  inconsistently. 


Number  4-92 


7 


Security  Awareness  Bulletin 


The  Harper  Comminee  Report  was  a  report 
to  the  Deputy  Under  Secretary  of  Defense  for 
Policy  by  the  Department  of  Defense  Industrial 
Security  Review  Committee  (December  1984) 
which  contained  an  analysis  of  the  effectiveness  of 
the  DoD  Industrial  Security  Program  and  offered 
recommendations  for  program  improvement.  The 
committee  was  convened  as  a  result  of  the  arrest 
of  James  Durward  Harper,  Jr.,  for  alleged 
espionage  activity  involving  a  DoD  contractor 
facility,  and  it  was  from  him  that  it  obtained  its 
name. 


In  counterpoint,  the  DIS  administration  of  the 
program  was  accused  of  having  become  so  struc¬ 
tured,  rigid,  and  inflexible  that  many  program 
managers  sought  relief  in  provisions  that  allowed 
them  to  be  exempt  from  regulations  of  the  DISP. 

Reports  continued  to  circulate  of  large  num¬ 
bers  of  government  ir«pectors  visiting  the  same 
facilities  to  look  at  the  same  things,  and  levying  ad 
hoc,  sometimes  whimsical,  requirements  on  their 
hosts.  As  a  result,  and  in  the  name  of  security, 
large  amounts  of  money  were  spent  to  build  un¬ 
necessary  facilities,  investigate  personnel  for  high 
clearances  and  accesses  of  questionable  need,  and 
control  information  that  was  protected  beyond  its 
sensitivity. 

There  had  been  little  support  from  any  quarter 
for  changes  to  industrial  security  policies  or  proce¬ 
dures  to  this  point.  Much  discussion,  and  some 
hand-wringing  continued  over  a  state  of  affairs 
that  was  recognized  as  problematic,  but  progress 
toward  improvement  was  noi  discernible. 

Disunity  existed  within  both  government  and 
industry  as  to  what  action  could  be  taken,  or  how 
action  might  be  taken  to  relieve  the  affects  on  con¬ 
tractors  of  rigid  and  dogmatic  enforcement  of  in¬ 
dustrial  security  procedures  on  the  one  hand,  and 
ad  hoc  requirements  of  multiple  customers  on  the 
other  hand.  Some  officials  were  loathe  to  act  be¬ 
cause  the  status  quo  was  their  desirable  condition. 
Others  felt  that  everything  was  all  right  and,  "if  it 
ain't  broke,  don't  fix  it."  Some  wanted  to  abolish 
all  SAPs  as  unnecessary,  excessive,  and  costly. 
Some  wanted  to  "reform"  the  industrial  security 
programs,  generally.  And,  there  were  those  in  in¬ 
dustry'  who  believed  that  taking  the  initiative  to 
offer  program  improvements  would  result  in 
prejudicial  criticism  of  their  efforts,  or  even  vindic¬ 
tive  retribution  against  their  firms  or  organizations 


by  government  officials  with  authority  over  the 
programs  concerned. 

Slowly,  during  the  mid-1980's,  industry  began 
to  become  more  involved  in  industrial  security 
policy  formulation.  Representatives  of  industry 
participated  in  both  the  Harper  Committee  and  the 
Stilwell  Commission.  Representatives  of  industry 
began  independently  to  formulate  p>ositions  that 
would  lead  to  a  single  industrial  security  program. 

With  the  encouragement  and  support  of 
several  key  government  officials,  industry  repre¬ 
sentatives  intensified  their  efforts  and  between 
March  and  July  1988,  generated  several  iterations 
of  a  "white  paper"  entitled,  "Toward  a  Rational  In¬ 
dustrial  Security  Program."  Despite  the  lack  of 
wide-spread  government  support,  industry  repre¬ 
sentatives  were  encouraged  to  document  and 
develop  supporting  data  for  changes  and  to  outline 
their  ideals  for  a  consolidated  program. 

On  the  basis  of  preliminary  but  unconfirmed 
data,  industry  began  to  build  a  plan  for  a  single 
program  and  documented  the  number  of  conflict¬ 
ing  and  overlapping  policies  and  redundancies 
while  identifying  associated  costs  for  all  security 
disciplines  and  programs. 

Concept  Development 

In  March  1988,  under  the  auspices  of  the 
Aerospace  Industries  Association  (AIA)  Industrial 
Security  Executive  Committee,  security  officials 
from  a  number  of  leading  defense  contractors  and 
the  government  began  working  together,  but  infor¬ 
mally,  on  a  program  to  standardize  security  prac¬ 
tices  within  industry.  The  Industrial  Security  Com¬ 
mittee  of  AIA  approved  continued  project  develop¬ 
ment.  It  was  recognized  that  continuing  top-level 


The  Stilwell  Commission,  named  in  honor  of 
its  chairman,  General  Richard  G.  Stilwell,  USA 
(Retired)(1917-1991),  was  established  by  the 
Secretary  of  Defense  as  the  DoD  Security  Review 
Commission  in  the  wake  of  arrests  of  three  retired 
and  one  active  duty  Navy  member  on  charges  of 
espionage.  The  Commission  was  directed  to  con¬ 
duct  a  review  and  evaluation  of  OoD  security 
policies  and  procedures  and  identify  any  sys¬ 
tematic  vulnerabilities  or  weaknesses  in  the 
programs.  It  produced  a  report  on  19  November 
1985,  “Keeping  the  Nation’s  Secrets." 


Security  Awareness  Bulletin 


8 


Number  4-92 


government  and  industry  support  was  critical  to 
the  success  of  the  iiutiative.  As  earlier  efforts  to 
"work  within  the  system"  had  failed,  AIA  execu¬ 
tives  along  with  other  industry  officials  introduced 
the  concept  with  a  "top  down"  approach  to  Chief 
Executive  Officers  (CEOs)  and  senior  government 
activities. 

During  an  AIA  Industrial  Security  Comnaittee 
meeting  in  May  1988,  there  had  been  extensive  dis¬ 
cussion  concerning  the  possible  form  and  sub¬ 
stance  of  something  like  a  National  Industrial 
Security  Program  (NISP).  Suggestions  were  ad¬ 
vanced  that  the  NISP  should  be  codified  in  federal 
law,  something  that  had  been  attempted  during 
the  late  1960's  without  success.  It  was  understood, 
too,  that  if  the  program  were  established  by  law,  it 
could  only  be  changed  or  modified  by  amend¬ 
ments  to  the  law,  a  situation  which  would  probab¬ 
ly  result  in  an  unacceptably  inflexible  program. 
Conferees  generally  agreed  that  an  Executive 
Order  would  probably  be  the  most  practical  instru¬ 
ment  of  authority. 

On  26  July  1988,  AIA  representatives 
presented  the  details  of  a  proposed  NISP  concept 
and  strategies  to  the  Assistant  Deputy  Under 
Secretary  of  Defense  (Counterintel.'igence  and 
Security)  and  the  Director,  Defense  Investigative 
Service.  Support  and  assistance  to  industry'  were 
offered  along  with  encouragement  to  continue  con¬ 
cept  development. 

In  August  1988,  AIA  sought  involvement  by 
the  American  Society  for  Industrial  Security  (.ASIS) 
which  committed  active  assistance.  The  National 
Classification  Management  Society  (NCMS)  and 
the  National  Security  Industrial  Association 
(NSIA)  also  brought  support  and  assistance  to  the 
NISP  initiative.  Industry  representatives  began  to 
accumulate  data  acquired  through  a  survey  of  a 
limited  number  of  member  companies  which 
provided  evidence  that  security  policies  and  proce¬ 
dural  requirements  generated  independently  by  in¬ 
dividual  government  departments  significantly  in¬ 
creased  costs  without  improving  security. 

To  further  support  the  belief  that  the  problems 
identified  in  the  earlier  survey  were  not  isolated, 
AIA  conducted  an  expanded  survey  of  some  of  the 
major  aerospace  companies  to  determine  whether 
the  security  issues  the  NISP  concept  addressed 
were  valid  on  a  broader  scale. 


Fourteen  companies  which  derived  a  total  of 
$32.8  billion  annually  from  government  contracts 
responded  to  the  survey.  The  fourteen  companies 
employed  a  total  of  340,000  cleared  people  and  had 
almost  twelve  million  classified  documents,  fifty- 
two  percent  of  which  were  accountable.’  This  was 
a  sizable  survey  to  counter  arguments  of  isolated 
problems  and  to  gain  support  for  more  cost- 
effective  security. 

Five  elements  of  existing  industrial  security 
programs  were  highlighted  in  industry's  survey: 
Personnel  Security;  Security  Briefings;  Security  In¬ 
spections;  Physical  Security;  and  Automated  Infor¬ 
mation  Security  (hardware,  software,  facilities,  and 
manpower). 

Industry's  total  reported  cost  from  this  survey 
was  $.8  billion.  It  projected  a  $2  to  $3  billion  cost 
avoidance  if  duplication  and  redundancy  with  no 
added  security  protection  could  be  eliminated 
through  establishment  of  a  single  industrial 
security  program. 

The  survey  highlighted  a  growing  need  for  a 
consolidated  program.  It  was  a  turning  point  in 
terms  of  gaining  the  attention,  influence,  and  sup¬ 
port  from  essential  components  of  the  government. 
Difficulty  arose,  however,  when  it  became  clear 
that  such  a  program  would  mean  giving  up  long¬ 
standing,  traditional,  and  parochial  practices.  The 
need  for  standardized  briefings,  inspections,  and 
universally-accepted  performance  standards  for  in¬ 
dustry  were  undeniable,  but  their  achievement 
remained  questionable.  It  would  require  each 
government  department  and  agency  to  accept  each 
other's  investigations,  accreditations,  and  inspec¬ 
tions,  based  on  the  same  standards.  Some  govern¬ 
ment  agencies  still  held  to  the  ideas  that  their 
programs  were  the  best  and  were  working  well. 

The  survey  statistics,  coupled  with  a  diminish¬ 
ing  funding  stream,  caused  support  in  government 
circles  to  grow.  From  late  1988  until  January  1990, 
AIA  zealously  kept  up  the  pressure  and  continued 
to  brief  government  officials  within  DoD,  the  State 
Department,  the  Central  Intelligence  Agency 
(CIA),  the  Department  of  Energy  (DoE),  the 
Federal  Bureau  of  Investigation,  and  others. 
Government  officials  expressed  enthusiasm  with 
encouragement  and  many  offcied  their  support.  A 


’  ■Accountable"  generally  refers  to  that  inlomnation  classified 
SECRET  and  above  conlroded  by  a  system  of  records  that  assures 
the  documentation  and  tracking  of  the  information  in  whatever  media. 


Number  4-*»2 


9 


Seciiriti/  Awareness  Bulletin 


briefing  was  held  for  Lt.  Gen.  Brent  Scowcroft, 
USAF  (Retired),  Assistant  to  the  President  for  Na¬ 
tional  Security  Affairs  in  November  1989.  He 
recited  persorud  frustrations  resulting  from  having 
repeatedly  to  complete  investigative  forms  despite 
his  long  years  in  the  service  of  his  coimtry  and  the 
number  of  previous  investigations  he  had  under¬ 
gone.  He  conunented  favorably  on  the  merits  of 
such  a  program  and  challenged  industry  to  con¬ 
tinue  briefing  the  concept  to  key  government  ex¬ 
ecutives. 

In  December  1989,  shortly  after  the  briefing  of 
General  Scowcroft,  Dr.  Robert  Gates,  then  Assis¬ 
tant  to  the  President  and  Deputy  for  National 
Security  Affairs,  requested  that  other  members  of 
the  NSC  be  briefed  on  the  concept. 

By  early  1990,  most  government  executives  in 
Washington  in  a  position  to  influence  and  create 
change  in  government  programs  had  been  briefed. 
Briefings,  speeches,  symposia  involving  industry 
and  government  representatives,  all  extolling  the 
virtues  of  a  NISP,  intensified  in  noise  and  number. 

In  March  1990,  General  Scowcroft  and  Dr. 
Gates  both  corresponded  with  the  President  of 
AlA  expressing  appreciation  for  industry's  efforts 
concerning  the  NISP.  Lieutenant  Generd 
Scowcroft  noted  that  "...codifying  industrial 
security  procedures  under  a  MSP  are  of  vital  im¬ 
portance...  We  continue  to  have  the  concept  under 
active  consideration  within  the  Government."  Dr. 
Gates  noted,  "the  NISP  concept  is  an  excellent  ex¬ 
ample  of  what  can  be  accomplished  if  industry  and 
government  work  together  on  problems  of  mutual 
interest." 

The  President  Acts 

Industry  had  provided  documentation  to  sup¬ 
port  its  position  on  the  need  for  a  NISP  and  a 
government  review  was  now  required  formally  to 
develop  information  on  the  issue. 

On  4  April  1990,  President  Bush  signed  a  Na¬ 
tional  Seairity  Review  entitled,  "The  National  In¬ 
dustrial  Security  Program,"  in  which  he  directed  a 
review  of  the  government's  industrial  security 
programs  to  determine  the  feasibility  of  estal> 
lishing  a  single  program  applicak'?  to  all  govern¬ 
ment  departments  and  agencies.  He  further 
directed  the  Secretary  of  Defense  to  take  the  lead 
and  coordinate  efforts  with  the  Secretary  of  Energy 
and  the  Director  of  Central  Intelligence. 


Significant  AIA  survey  findings  included: 

•  Fourteen  govenunent  agencies  imposed 
341  security  regulatioirs  and  directives  on 
industry. 

•  Twelve  government  agencies  conducted 
multiple  inspections  at  each  facility  (one 
contractor  reported  fifty-five  inspections 
in  one  year  requiring  442  man-days  of  ef¬ 
fort).  One  contractor  reported  150  SAPs 
each  requiring  two  annual  inspections. 

•  One-third,  or  105,400  cleared  employees, 
completed  an  average  of  eight  sets  of  in¬ 
vestigative  forms  for  six  different  agencies. 

•  An  equal  number  of  cleared  employees 
(105,400)  required  an  average  of  seventeen 
separate  security  briefings. 

•  Industry's  total  reported  cost  from  this  sur¬ 
vey  was  $.8  billion.  It  projected  a  $2  to  $3 
billion  cost  avoidance  if  duplication  and 
redundancy  with  no  added  security 
protection  could  be  eliminated  through  es¬ 
tablishment  of  a  single  industrial  security 
program. 


The  Government  Review — Phase  I 

The  Secretary  of  Defense  delegated  respon¬ 
sibility  for  the  MSP  review  to  the  Under  S^etary 
of  Defense  for  Policy  on  19  April  1990. 

Six  govenunent  agencies  (State,  Treasury,  Ener¬ 
gy,  the  Nuclear  Regulatory  Commission,  the  Attor¬ 
ney  General/Federal  Bureau  of  Investigation  and 
the  Central  Intelligence  Agency)  and  13  DoD  agen¬ 
cies  participated  in  the  review;  industry  was  kept 
abreast  of  developments  through  continuing  coor¬ 
dination  among  industrial  associations  and  the 
review  coordinator. 

A  survey  questionnaire  designed  to  elicit 
similar  information  as  that  documented  by  the  ear¬ 
lier  industry  sur\'ey,  was  developed  and  provided 
to  all  government  departments  and  agencies  par¬ 
ticipating  in  the  review.  It  produced  information 
that  convinced  many  more  government  officials 
that  changes  were  needed,  as  the  total  costs  (both 
direct  and  indirect)  for  industrial  security  were  es¬ 
timated  at  $13.8  billion. 


Security  Awareness  Bulletin 


10 


Number  4-92 


the  B^sidenfs  National  Security  Review 
concerning  the  NISP  sought  answers  to  the  fol¬ 
lowing  questions: 

•  How  can  we  standardize  security  train¬ 
ing? 

•  Can  we  develop  uniform  inspection 
compliance  standards? 

•  What  single  set  of  baseline  standards 
can  we  develop  applicable  to  all  govern¬ 
ment  agencies  and  departments? 

•  Shoxild  there  be  layered  security  con¬ 
trols? 

•  What  should  industry's  role  be  in  the 
NISP? 

•  What  shifts  in  priorities  and  resources 
are  needed  to  effect  a  NISP? 

•  What  changes  are  needed  to  improve 
security  effectiveness  and  ensure  cost  ef¬ 
ficiency? 

•  Which  agencies  and,  departments  should 
develop  standcirds  and  procedures  and 
who  should  have  oversight  respon¬ 
sibility? 


The  government  survey  provided  data  on  the 
industrial  security  program  that  were  heretofore 
unknown  or  not  publicized.  For  example: 

•  The  government  has  more  then  15,000 
cleai^  contractor  facilities  employing 
more  than  1.5  million  cleared  contractor 
employees. 

•  Various  rules  and  regulations  implement 
or  supplement  the  basic  executive  orders 
and  legislation.  They  include  47  different 
standards,  manuals,  and  directives  that  cre¬ 
ate  a  significant  regulatory  burden  to  in¬ 
dustry  and  government. 

•  Various  agencies  sponsor  programs 
designed  to  maintain  threat  awareness  in 
industry.  Virtually  all  agencies  and  depart¬ 
ments  of  government  have  security  aware¬ 
ness  training  programs,  briefings,  and 


materials  available  for  use  by  their  contrac¬ 
tors,  but  they  are  all  poorly  utilized. 

•  A  lack  of  uniform  personnel  security  re¬ 
quirements  and  reciprocity  of  investiga¬ 
tions  throughout  the  govenunent  cause  un¬ 
necessary  costs  as  a  result  of  redimdant  in¬ 
vestigations  and  lost  time  while  persoimel 
wait  for  clearance. 

•  Special  activities  (sensitive  compartmented 
information,  SAPs,  and  Energy /Restricted 
Data  (E/RD)  and  programs  should  have 
supplemental  controls  only  if  it  has  been 
determined  that  baseline  security 
programs  do  not  provide  adequate  protec¬ 
tion. 

•  Security  oversight  of  industry  is  applied  in¬ 
consistently  by  government  agencies  with 
generally  no  reciprocity  for  facility  ac¬ 
creditations,  certifications  or  inspections 
among  agencies  and  departments. 

•  Most  departments  and  agencies  have  no 
mechanism  for  determining  the  costs  of 
the  industrial  security  program.  Security 
costs  are  generally  embedded  in  other  pro¬ 
gram  elements.  When  estimates  were 
provided,  they  seemed  low.  There  were 
no  means  available  within  the  government 
for  validating  and  separating  security  costs 
from  other  program  costs. 

The  review  confirmed  the  government's  use  of 
multiple  rules  to  protect  information  of  the  same 
sensitivity;  inconsistent  application  and  enforce¬ 
ment  of  those  rules;  and  an  inability  to  determine 
program  costs. 

The  Response  to  the  President 

The  report  to  the  President^  following  the  ini¬ 
tial  program  review  indicated  that  the  concept  of  a 
national  program  for  security  in  industry  is 
feasible  and  desirable.  Moreover,  the  S^retaries  of 
Defense,  Energy,  Treasury,  the  DCI,  the  Attorney 
General  and  the  Chairman,  NRC,  all  generally  sup¬ 
ported  the  concept  of  a  single  integrated  system  of 
industrial  security  for  classified  programs.  The 
report  also  contained  the  general  consensus  of  both 
government  and  industry  representatives  that  SCI, 


^  A  Report  to  the  President  by  the  Secretary  of  Defense,  'The  National 
Industrial  Security  Program,*  November  1990. 


Number  4-92 


11 


Security  Awareness  Bulletin 


SAPs,  and  Energy-unique  activities  should  be  sub¬ 
ject  to  supplemental  controls. 

The  report  proposed  that  an  Interagency  Task 
Force  led  by  the  Secretary  of  Defense,  Ae  DCI,  and 
die  Secretary  ot  Energy,  with  industry  participa¬ 
tion,  design  a  national  industrial  security  program 
to  be  implemented  under  the  general  oversight  of 
the  Executive  Office  of  the  President. 

Again,  the  President  Concurs 

On  6  December  1990,  the  President  concurred 
in  the  plan  and  directed  that  a  task  force  develop 
elements  of  a  NISP  as  outlined  in  the  report.  The 
President  further  requested  that  recommended 
policy  changes  be  provided  to  the  National 
Security  Council  by  1  September  1991.^ 

The  Review — Phase  II 

The  Assistant  Deputy  Under  Secretary  of 
Defense  (Coimterintelligence  and  Security)  was 
designated  the  responsible  official  for  leading  and 
directing  the  effort.^ 

The  NISP  Interagency  Task  Force  consisting  of 
an  executive  committee,  steering  committee,  and 
10  working  groups,  was  formaUy  established  on  22 
January  1^1.  The  steering  committee  was  directed 
to  report  to  an  executive  committee,  members  of 
whi(^  had  departmental  or  agency  program  ap¬ 
proval  authority  for  their  respective  departments. 
An  eleventh  working  group,  the  Monitoring  and 
Evaluation  Group,  was  established  to  serve  as  the 
focal  point  for  all  activities  and  to  provide  support 
to  the  steering  committee. 

The  division  of  labor  among  the  working 
groups  was  designed  so  that  each  would  con¬ 
centrate  on  a  separate  security  discipline.  In  some 
cases,  like  that  of  the  Information  Seauity  Work¬ 
ing  Group,  it  was  determined  desirable  to  form 
sub-groups  to  deal  with  the  clearly  separate  areas 
of  SAPs,  SCI,  and  Energy-related  programs.  It  was 
the  consensus  of  the  entire  task  force  that  a  work¬ 
ing  group  dealing  with  threat  be  established  to 
determine  not  only  changing  threats  as  they  affect 


^  PiMldanrs  MemoranAjm  to  the  Secretary  of  Defense,  6  December 
1080. 


^  Based  on  an  organizatiottal  change  within  the  Office  of  the 
Secretary  of  Defense,  DoD  resporrsibiiity  for  the  NISP  was  trans- 
torrsd  to  the  Deputy  Assistant  Secretary  of  Defense  (Counterintel- 
Igofwa  and  Security  Countenneasures)  In  September  1991. 


policy  formulation,  but  improved  means  of  com¬ 
municating  the  threats  to  industry. 

Working  groups  comprised  of  experts  from 
government  and  industry  labored  to: 

•  Conduct  a  comprehensive  regulatory 
review 

•  Develop  an  instrument  of  authority  for  a 
single  industrial  security  program 

•  Develop  uniform  s^d^dized  Security 
policies 

•  Establish  a  mechanism  for  determining 
complete  industrial  security  costs,  and 

•  Ensure  completion  of  ongoing  personnel 

security  initiatives  for  a  single  scope 
background  investigation  applicable  to 
all  government  departments  and  agen¬ 
cies.  * 


Formation  of  the  working  group  on  Threat, 
and  creation  of  the  Monitoring  and  Evaluation 
Working  group  were  two  of  the  first  formal  ex¬ 
amples  of  the  ability  of  a  combined  group  of 
government  and  industry  representatives  to 
achieve  consensus  on  issues  related  to  a  NISP. 

Industry,  government,  and  all  affected  "com- 
munities"®  were  involved  in  the  working  groups 
and  the  steering  committee.  Each  workfog  group 
was  headed  by  a  government  and  industiy  co¬ 
chair.  The  working  groups  functioned  as  teams  to 
design  the  future  program  elements  beginning 
with  basic  policies,  proceeding  to  details  that 
would  provide  the  functional  guidance  to  im- 
plementers.  This  concept  allowed  the  formulation 
of  segregable  policies,  or  elements,  that  could  be 
approv^  and  implemented  immediately  despite 
what  might  happen  to  the  NISP  in  its  entirety.  It 
was  decided  that  each  working  group  would 
review  ciurent  policies  and  procedures,  in  toto  and 
by  sub-discipline,  respectively,  in  order  to  preserve 
that  which  works  weU  and  which  would 
presiunably  work  well  in  the  future.  The 
preserved  elements  of  current  policies  and  proce- 


^  The  term  *communi1ies*  refers  to  groups  of  like  organizations,  or  or¬ 
ganizations  with  related  missions  and  functions,  e.g.,  the  Intelligence 
Community. 


StcHrttjf  Awarmeu  Bulletin 


U 


Number  4-92 


Figure  1.  National  Industrial  Security  Program 
Task  Force  Chart  (August  1992) 


National  Security  Council 

1 

_ 1 _ 1 

Executive  Committee 

DoD  DOE  DCI 

_ 1 _ 

Steering  Committee 

Chairs:  Stewart,  DoD  Fxec.  Secretary:  NISAC  Chairman 

Harry  Volz,  Grumman  John  Elliff,  DoD 

Members:  DOE.  CIA,  DIS,  ISOO,  State,  Justice,  0MB,  CCISCMO,  NRC 


Working  Group  Co-Chairs 


Monitoring  &  Evaluation 


Helmut  Hawkins,  OoD 
Fred  Demech,  TRW 


Regulation 


Greg  Gwash,  OiS 
James  Graves,  Litton 


Information  Systems 


Physical 


William  Desmond,  DOE 
Robert  Safreed,  TRW 


Education  &  Training 


George  Rothstein,  NSA 
Robert  Atkins,  General  Electric 


Ev  Gravelle,  DoDSI 
Mike  Nicholson,  Westinghouse 


international  | 

FOCI 

John  Frields,  DoD 

Daniel  Muscat,  Smiths 

Global¬ 

ization 

Charles  Wilson,  DoD 
Barry  DeRoze,  TRW 

Information  \ 

NSI 

Steven  Garfinkel,  ISOO 

Jack  Chatowski,  TRW 

SCI 

Ken  Renshaw,  CIA 

Robert  Greer,  TRW 

Energy/ 

RD 

Larry  Wilcher,  DOE 

Ernie  Conrads,  West’house 

SAP 

Dick  Williams,  DoD 

Lou  Bouchard,  Grumman 

Personnel 


Robert  Iwai,  CIA 
Larry  Howe,  SAIC 


Resources 


Helmut  Hawkins,  DoD 
Lynn  Mattice,  Northrop 


Oversight  &  Compliance 


Mark  Borsi,  DIS 
Jed  Selter,  Boeing 


Threat 


Harry  Brandon,  FBI 
Edgar  Best,  Hughes 


Number  4-92 


13 


Security  Awareness  Bulletin 


dures  would  then  serve  as  the  foundation  for  new 
innovative  elements  that  would  complete  the  re¬ 
quirements  for  a  program. 

An  early  example  of  greater  efficiency  in 
federal  policy-making  emerged  from  the  NISP 
process.  A  single  scope  background  investigation 
for  access  to  top  secret  and  SCI  had  been  under 
consideration  in  the  government  for  a  number  of 
years.  When  directed  by  the  President,  it  became 
an  objective  of  the  NISP  Task  Force  also.  Agree¬ 
ment  concerning  its  requirements  was  achieved 
with  relative  speed  and  resulted  in  a  National 
Security  Decision  by  the  President  on  21  October 
1991.  It  is  also  an  example  of  the  development  of  a 
segregable  element  of  policy. 

The  working  groups  were  established  to  deal 
with  discreet  security  disciplines.  A  notable  excep¬ 
tion  is  the  Regulation  Working  Group  which  must 
cross  all  security  disciplines  as  it  works  toward  its 
objective  of  establishing  a  single  regulation.  That 
regulation,  to  be  called  the  National  Industrial 
Security  Program  Operating  Manual  (NISPOM), 
will  include  the  set  of  rules  by  which  the  NISP  will 
function,  along  with  instructions  for  both  govern¬ 
ment  and  industry.  Other  working  groups  will 
feed  the  Regulations  Working  Group  with  the 
necessary  information  and  material  to  establish  the 
rules. 

Working  group  chairpersons  (a  government 
and  industry  representative  co-chaired  each  work¬ 
ing  group)  were  selected  by  the  steering  commit¬ 
tee.  Chairpersons  were  responsible  for  creating 
their  own  groups,  preparing  terms  of  reference  by 
which  to  operate,  ensuring  appropriate  repre¬ 
sentation  from  government  and  industry,  and  for 
establishing  an  agenda.  The  charters  and  objec¬ 
tives  of  each  group  were  formalized  and  submitted 
to  the  steering  committee  for  approval. 

By  late  March  1991,  most  working  groups  were 
well  into  the  effort,  and  on  2  May  1991,  the  steering 
committee  provided  an  interim  report  to  the  execu¬ 
tive  committee.^  The  report  depicted  the  task  force 
organization,  outlined  NISP  initiatives,  and 
provided  a  summary  of  accomplishments.  The 
report  confirmed  support  by  all  committee  mem¬ 
bers  for  establishing  a  single  program  for  industry. 

The  September  1991  Report  to  the  President^ 
advised  that  the  NISP  had  been  accepted  by 

®  NISP  Steering  Committee  Interagency  Task  Force  Status  Report 
on  the  NISP,  2  May  1991. 


government  and  industry  officials  and  the  task 
force  had  successfully  developed  the  critical  com¬ 
ponents  of  the  NISP.  Supplemental  standards 
were  included  for  SCI,  SAPs,  and  Energy/RD 
programs.  The  report  advised  that  oversight  or¬ 
ganizations  and  responsibilities  for  the  NISP 
would  utilize  existing  offices,  departments,  and 
agencies  and  assign  to  them  the  responsibilities  for 
the  NISP,  eliminating  the  need  to  create  a  new  or¬ 
ganization  for  oversight  purposes.  The  concept  of 
"minimum  standards"  for  security  had  been 
abolished — stated  standards  would  be  the  only 
standards.  The  report  further  stated  that  the 
responsibilities  of  the  Secretaries  of  Defense  and 
Energy,  the  NRC  and  the  DCI,  derived  from  their 
statutory  and  presidentially  delegated  authorities, 
had  been  preserved. 

The  report  included  a  "critical  path"  for  the 
next  and  succeeding  phases  which  outlined  sig¬ 
nificant  events  and  important  time-lines  by  which 
full  implementation  of  the  NISP  could  be  realized 
by  the  end  of  1995.  The  steering  committee  out¬ 
lined  the  needed  actions  through  1995  and  noted 
that  the  majority  of  other  changes  could  be  imple¬ 
mented  by  the  end  of  1993. 

On  29  January  1992,®  the  President  noted  in  a 
memorandum  to  the  Secretary  of  Defense,  "The 
government-industry  task  force  you  established 
has  made  considerable  progress  toward  develop¬ 
ment  of  a  single,  coherent,  and  integrated  program. 
This  remarkably  collaborative  effort  between 
government  and  industry  will  lead  to  significant 
improvements  in  the  security  of  our  Nation."  The 
President  continued,  "1  am  especially  pleased  with 
the  projected  time  frame  in  which  you  intend  to 
fully  implement  this  vital  program,  which  will  pro¬ 
vide  cost-effective  and  security  development  and 
delivery  of  systems  essential  to  our  national 
security." 

Current  Status 

In  June,  1992,  a  draft  executive  order  (EO)  es¬ 
tablishing  the  NISP  was  sent  to  the  National 
Security  Council.  The  Office  of  Management  and 
Budget  (OMB)  is  completing  coordination  within 
the  Executive  branch.  When  signed,  the  current 


^  The  National  Industrial  Security  Program — A  Report  to  the  Presi¬ 
dent,  September  1991. 


®  The  President's  Memorandum  to  the  Secretary  of  Defense  of  29 
January  1992  on  the  National  Industrial  Security  Program. 


Security  Awareness  Bulletin 


14 


Number  4-92 


draft  of  the  NISP  EO  calls  for  publication  of  the 
NISP  Operating  Manual  within  one  year. 

On  June  17, 1992,  the  first  draft  of  the  National 
Industrial  Security  Program  Operating  Manual 
was  forwarded  to  the  other  working  groups  by  the 
Regulation  Working  Group  for  preliminary  coor¬ 
dination  and  comment. 

f  2.  Proposed  \ISP  Stnictiirc 


NISP  Policy  Advisory  Committee 
(Government  &  Industry)  (^J 


Secretary 

■ 

Director  of 

Secretary 

of 

■ 

Central 

of 

Defense  0 

1 

Intelligence  0 

Energy  0 

1 

Sensitive 

■ 

Compartmented 

Atomic  Energy 

Executive  Agent 

■ 

Information  (SCI) 

Act  Programs 

■ 

Programs/Intell 

(RD/FRD) 

■ 

Sources  &  Methods 

1 

1 - 

All  Executive  Branch  Departments  &  Agencies 


Nuclear 
Regulatory 
Commission  0 


Atomic  Energy 
Act  Programs  and 
Title  to,  CFR 
(Parts  25  and  95) 


I 


1  Pwide  overall  NISP  policy  direction 

2  Oversee  Executive  Branch  Department  Agency  actions  to  ensure  compliance  with  the  NISP 
subject  to  statutory  or  presidentially  delegated  authorities 

•  Issue  implementing  directives 

•  Provide  guidance 

•  Monitor  and  evaluate  NISP  comp'-  ince 

•  Coordinate  and  recommend  NISP  policy  changes 

•  Review  National  Industrial  Security  Program  Operating  Manual  iNISPOMi  and  agency  regulations 

•  Monitor  NISP  for  improvements 

•  Report  annually  on  the  NISP  to  the  President 

•  Chair  NISPPAC 

3  Advise  on  all  matters  concerning  the  policies  of  the  NISP  including  recommended  changes  and  issues  m  dispute 

4  Issue  and  maintain  the  NISPOM  including  special  supplements 
Inspect  and  monitor  contractor,  licensees,  and  grantees 

5  Implement  the  NISP 


Number  4-92 


15 


Security  Awareness  Bulletin 


New  DoDSI  Correspondence  Course 


Basic  Industrial  Security  for  User  Agency  Personnel 

DS  2101 


The  Department  of  Defense  Security  Institute  is 
proud  to  announce  that  its  new  correspondence 
course,  Basic  Industrial  Security  for  User  Agency 
Personnel  (BISUAP),  DS  2101,  is  available  for  enroll¬ 
ment.  BISUAP  will  replace  our  resident  Industrial 
Security  Basic  Course,  which  will  no  longer  be  of¬ 
fered. 

BISUAP  addresses  the  following  topics: 

•  the  Facility  Security  Clearance 

•  Personnel  Security  Clearances 

•  Visitor  Control 

•  Classification  Management 

•  Safeguarding  Classified  Information 

•  Automated  Information  Systems 

•  International  Activities 

•  Violations  and  Con. ^  ronises 

•  Inspections 

Completion  of  Structures  of  Industrial  Security 
(SIS),  DS  2100,  is  strongly  urged  for  those  who  will 
be  taking  BISUAP,  DS  21 01.  Prior  completion  of  both 
of  these  correspondence  courses  is  mandatory  for 
personnel  who  will  attend  the  User  Agency  Inspec¬ 
tor  course  at  the  DoDSI. 

SIS  covers  patterns  of  organization  prescribed  by 
state  laws  to  regulate  commercial  enterprises  (busi¬ 
ness  structures),  procedures  set  up  under  federal 
laws  to  regulate  governmental  purchases  (the 
defense  acquisition  cycle),  and  organizations  formed 
under  executive  orders  to  promote  national  security 
(such  as  the  Defense  Industrial  Security  Program  and 
the  Defense  Investigative  Service). 

BISUAP  goes  on  to  point  out  the  basic  require¬ 
ments  imposed  on  cleared  defense  contractors — and 
on  the  User  Agencies — in  the  Industrial  Security 


Manual  for  Safeguarding  Classified  Material  (ISM), 
DoD5220.22-M. 

We've  designed  BISUAP  for  User  Agency  per¬ 
sonnel  who  require  a  basic  knowledge  of  industrial 
security,  such  as: 

•  Contracting  officers  and  inspectors 

•  Security  interns  who  require  knowledge  of 
industrial  security 

•  Security  specialists  who  are  responsible  for 
one  aspect  of  security  for  a  classified  contract, 
such  as  persormel  security,  physical  security, 
or  information  security. 

•  Personnel  newly  assigned  to  a  special  access 
program  (SAP). 

•  Military  personnel  entering  upon  a  3-year  as- 
signment  in  the  area  of  security. 


-3ASrG 

INDUSTRIAL 

-  “SRGTIRITY,  ;  V] 

-  for  ^ 

U  S  E  R 


A&EiNTGY  — 
-RYlRSOlSfHEL' 


! 
a 


Written  as  an  orientation  for  User  Agency  per¬ 
sonnel,  BISUAP  is  also  open  to  DIS  Industrial 
Security  Representatives  and  the  Facility  Security 
Officers  in  industry  and  members  of  their  staffs. 
Enroll  by  submitting  a  DA  Form  145  to  the  Army 
Institute  for  Professional  Development  (IPD)  in 
Newport  News,  Virginia.  DA  Form  145  is  available 
from  cognizant  security  offices,  DIS. 


Security  Awareness  Bulletin 


16 


Number  4-92 


The  Industrial  Security  Manual  on  computer  diskettes 


Number  4-92 


17 


Securift/  Awareness  Bulletin 


You  Can  Host  These  Courses  On-site  at  your  Facility 
(Industry  or  Government) 


Security  Briefers  Course  (SBC) 

5220.13, 2.5  days 

Purpose:  To  improve  your  effectiveness  as  a 
security  education  briefer.  You  will  receive  in¬ 
struction  on  how  to: 

•  prepare  a  briefing  plan; 

•  design  and  use  briefing  aids; 

•  present  your  briefings  in  a  clear  and 
interesting  manner;  and 

•  evaluate  live  briefings. 

As  the  "Security"  in  the  course  title  suggests,  the 
briefings  must  address  security  requirements,  but 
this  is  not  the  emphasis  of  the  course.  The  course 
emphasis  is  on  accomplishing  the  objectives  listed 
above  so  that  you  become  more  skilled  and  more 
comfortable  at  speaking  in  front  of  others. 


Train-the-Trainer  Course  (TTT) 

5220.13a,  2  days 

Purpose:  To  train  you  to  teach  the  SBC.  This 
workshop,  conducted  on  the  2  days  before  a 
scheduled  SBC,  prepares  you  to  be  an  instructor 
for  the  SBC.  You  will  receive  instruction  by 
DoDSI  staff  on  how  to: 

•  use  the  SBC  materials; 

•  present  selected  lessons  in  the  SBC; 

•  facilitate  the  preparation  of  briefings; 

•  conduct  practice  briefing  sessions;  and 

•  evaluate  live  briefings. 

Under  DoDSl  supervision,  you  will  then  spend  the 
next  2.5  days  teaching  your  first  SBC. 


If  you  are  considering  participating  in  the  TTT,  it  is  suggested  that  you:  be  responsible  for  your 
organization's  security  briefing  program;  be  an  experienced  security  briefer  or  a  graduate  of  the  SBC;  have 
a  need  to  train  others  to  prepare  and  present  security  briefings;  and  have  a  working  knowledge  of  security 
requirements.  If  you  want  to  learn  hoiu  to  brief — choose  the  SBC. 

To  host  the  courses  described  above,  please  call  Del  Carrell,  DoDSI  at  (804)  279-5314  or  DSN  695-5314. 

These  courses  are  held  in  succession.  The  TTT  precedes  the  SBC. 

To  host  the  SBC,  you  must  be  able  to  provide: 

□  one  main  classroom  for  24  students 

□  3  breakout  rooms  for  6  students  each 

□  A-V  equipment  for  all  4  rooms 

(Overhead  projectors,  screens,  and  writing  surfaces  for  each  room) 

□  At  least  two  of  the  instructors  and  preferably  more  for  the  TTT. 

□  An  on-site  coordinator 

□  Invitations  to  other  security  organizations  in  your  area  in  order  to  fill  a  class  of  24. 

The  Department  of  Defense  Security  Institute  (DoDSI)  will: 

✓  Provide  the  lead  instructor  and  assume  responsibility  for  the  teaching  success  of  the  course. 

✓  If  necessary,  provide  security  personnel  from  other  organizations  to  help  teach  the  course. 

✓  Provide  two  full  days  of  training  for  the  instructors  prior  to  starting  the  course. 

✓  Provide  the  instructional  materials  in  sufficient  quantities  for  24  students. 

✓  Help  the  trainers  teach  the  Security  Briefers  Course. 


Security  Awareness  Bulletin 


18 


Number  4-92 


Security  Briefers  Course  Dates  and  Locations 

The  following  organizations  are  sponsoring  the  Security  Briefers  Course: 


1 


2 


3 


4 


5 


Number  4-92 


September  23-25, 1992 

USARMY-DPTMS 
at  Ft.  Belvoir,  VA 

PCX:.-  Ms.  Allison  Troy  (703)  805-2416,  (DSN)  655-2416 


September  29-October  1, 1992 

JIGSAG  (Joint  Industry  -  Government  Security  Awareness  Group) 
at  American  Management  Systems 
1777  N.  Kent  Street,  14th  floor 
Arlington,  VA  22209 

POC;  Ms.  Susan  Davis  (703)  560-5000  x4778 
Mr.  Ron  Thinnes  (703)  556-6518 


October  28-30, 1992 

ISAC  (Industrial  Security  Awareness  Council)  Salt  Lake  City 

at  Paramax  Systems  Corporation 

640  North  2200  West 

Salt  Lake  City,  UT  84116-0225 

POC:  Mr.  Joe  Colton  (801)  594-5615 


November  4-6, 1992 

VSAC  (Vandenberg  Security  Awareness  Council) 

at  Vandenberg  Air  Force  Base,  CA 

POC:  Ms.  Teresa  Alarcio  (805)  928-5711  x221 


April  28-30, 1993 
JIGSAG 

at  Center  for  Innovative  Technology 
Reston,  VA 

POC:  Ms.  Susan  Davis  (703)  560-5000  x  4778 
Mr.  Ron  Thinnes  (703)  556-6518 

Please  call  the  Point  of  Contact  for  course  specifics  and  enrollment  information. 


19 


Security  Awareness  Bulletin 


Lethal  Weapons  Too 


We  have  quantities  of  a 
computer  seciuity 
poster  available  for  the 
asking.  Originally 
produced  by  American 
Forces  Information 
Service.  Just  call  or 
write  for  your  free 
copy.  17"  X  22"  color 
poster  comes  folded 
flat. 


(804)  279-4223 
Attn:  EPD 

DoD  Security  Institute 
c/o  DGSC 

Richmond,  VA  23297-5091 


New  Video . . . 

National  Industrial  Security  Program 

Date  1992 

Video  #1  NISP  Status  Date:  March  1992  Length:  09:45 

Video  #2  NISP  Overview  Date:  February  1991  L 

NISP  Status  Date:  March  1992 

Cost  per  videotape:  $17.50  for  VHS  $27.50  for  3/4" 

(price  includes  shipping  &  handling) 

Order  from:  FilmComm 

641  North  Avenue 
Glendale  Heights,  IL  60139 
(708)790-3300 
fax:  (708)790-3325 

Summary:  The  Boeing  Company  has  been  involved  in  a 
national  effort  to  replace  the  many  redundant 
Government  security  programs  levied  on  industry  with  one  cohesive,  integrated  set  of  requirements. 

This  program  has  bmome  known  as  the  National  Industrial  Security  Program  (NISP).  Boeing,  in  support 
of  the  NISP,  has  produced  two  videos:  an  overview  of  the  program  and  more  recently  an  update  status 
video. 


Security  Awartnee*  Bulletin 


20 


Number  4>92 


The  Defense  Treaty  Inspection  Readiness  Program 
and  START  Special  Access  Visits 


ByMarkBorsi 
Oii^,  Special  Actiona  Branch 
Dt^enae  Inveatigative  Service 


Is  your  facility  ready  for  a  START  treaty  inspec¬ 
tion?  Before  you  get  too  alarmed,  be  advised  d\at 
this  applies  only  to  a  limited  number  of  military 
and  defense  contractor  facilities  which  might  be 
subject  to  inspection  under  START  or  one  of  the 
other  arms  control  treaties.  In  additicm,  the  START 
itself  is  awaiting  ratification  by  the  Senate  and  of 
course  will  not  be  in  effect  tmtil  this  happens. 

But  the  writing  on  the  wall  is  that  at  some 
point  in  the  near  future  we  must  have  in  place  ap¬ 
propriate  security  coimtermeasures  at  each  "inspec- 
table  facility"  in  anticipation  of  a  possible  treaty 
inspection.  The  Defense  On-Site  Inspection  Agen¬ 
cy  working  with  the  Defertse  Investigative  Service 
will  play  the  leading  role  in  assisting  contractors  to 
prepare  themselves  for  such  an  inspection. 

The  DTIRP,  design  and  purpose 

According  to  its  charter.  The  Defense  Treaty  In¬ 
spection  Readiness  Program  (DTIRP)  is  a  multidis- 
dplined,  all-source  security  vulnerability 
assessment  program  utilizing  intelligence, 
coimterinteUgence,  traditional  security  and  opera- 
ticms  security  (OPSEQ  methodologies.  This  essen¬ 
tially  means  that  no  botmdaries  are  being  drawn 
concerning  where  we  obtain  information  about  a 
potential  threat  and  how  we  are  going  to  counter 
that  threat  The  purpose  of  the  E>TIRP  is  to  iden¬ 
tify  critical  information  and  technology,  assess  vul¬ 
nerability  and  recommend  cost  effective  security 
countermeasiues.  The  program  was  created  to  pro¬ 
vide  timely,  informed  recommendations  to  policy 
decision  makers,  program  managers  and  facility 
managers  in  both  government  and  industry.  It  is 
desigired  to  foster  awareness  and  ensure  under¬ 


standing,  enabling  everyone  to  appropriately 
prepare  for  the  possibility  of  a  treaty  inspection. 

A  Multi-agency  effort 

The  DTIRP  employs  technical  and  subject  mat¬ 
ter  experts  to  provide  objective  aiulyses  and 
recommendations  to  assist  in  the  development  of 
security  countermeasures  for  each  iirspectable 
facility.  On  25  June  1992  the  Director,  On-Site  In¬ 
spection  Agency  was  appointed  as  the  Executive 
Agent  for  Ae  DTIRP.  Program  policy  direction  is 
provided  by  the  Deputy  Assistant  Seaetary  of 
Defense,  Counterintelligence  and  Security  Counter¬ 
measures.  Partidpaiingagenciesprovidingperson- 
nel  and  support  include  the  Defense  Investigative 
Service,  the  Defense  Intelligence  Agency,  the 
Federal  Bureau  of  Investigation,  the  Central  Intel¬ 
ligence  Agency,  the  National  Security  Agency,  the 
Community  CoimterinteUigence  and  Security 
Countermeasures  Office,  and  the  Army,  Navy  and 
Air  Force.  The  DTIRP's  continuing  mission  is  to  as¬ 
sist  die  government  and  contractor  commrinity  in 
providing  coimterintelligence  and  security  counter¬ 
measiues  (CI&SCM)  support  in  connection  with  in¬ 
spection  of  U.S.  facilities  vmder  arms  control 
treaties. 

Vulnerability  assessments 

The  principal  product  of  the  DTIRP  is  a  report 
(classifi^  appropriately)  focusing  on  arms  control 
treaty  specific  vulnerabilities  at  inspectable  sites. 

To  date  the  DTIRP  has  conducted  more  than  thirty 
assessments  of  START  declared  inspectable  sites, 
both  military  and  industrial.  Initially  developed  in 
support  of  Strategic  Arms  Reduction  Treaty 
(START)  preparations,  the  DTIRP  has  expanded  to 
provide  support  to  all  arms  control  treaties  and 
agreements.  Current  examples  include  the  Open 
Skies  Treaty,  the  Chemical  Weapons  Treaty,  and 
the  Conventional  Forces  in  Europe  Treaty. 


Number  4-92 


21 


Security  Awareness  Bulletin 


Special  Access  Visits 

Arms  control  treaties  include  various  "inspec¬ 
tion  regimes"  or  procedures  established  by  the 
treaty  involving  foreign  representatives  inspecting 
U.S  facilities.  In  some  cases,  the  U.S.  knows  in  ad¬ 
vance  which  facilities  will  be  visited.  In  these 
cases,  DTIRP  studies  are  used  to  prepare  the 
hicility  f(»r  an  inspection.  However  some 
"regimes"  allow  for  the  inspection  of  "imdeclared" 
fodlities.  The  START  Treaty  has  such  a  provision 
which  is  called  a  Special  Access  Visit  (SA^.  Essen¬ 
tially,  the  SAV  provision  was  established  to  ad¬ 
dress  the  possibility  of  cheating  by  allowing  a 
sigitatory  to  tfve  treaty  to  challenge  and  mspect 
noivdeclared  facilities.  Forhmately,  not  ail  SAV  re¬ 
quests  will  result  in  actual  inspectioiu.  In  fact,  in 
these  cases  our  objective  is  to  resolve  a  challenge 
without  allowing  a  visit  at  all.  A  U.S.  Government 
response  may  be  to  (1)  allow  an  inspection,  (2) 
resolve  a  challenge  by  some  alternative  means,  or 
(3)  refuse  to  allow  an  inspection  to  take  place. 

However,  SAV  challenges  do  create  imique 
security  concerns  because  the  government  has  a 
very  short  time  to  determine  the  implications  of  al¬ 
lowing  an  intrusive  inspection.  To  deal  with  these 
concerns  the  DTIRP  is  involved  in  START  plan¬ 
ning  for  Special  Access  Visits;  developing 
databases  which  will  allow  us  to  perform  statistical 
analyses  and  systeirratic  tracking;  and  working  to 
provide  training,  information,  and  assistarKe. 

What  la  being  done  for  inspectable  facilities: 

In  addition  to  making  vulnerability  assess¬ 
ments,  the  DTIRP  staff  plaiu  to  evaluate  facilities 


for  vulnerability  and  likelihood  of  facing  a  SAV 
challenge,  allowing  the  government  to  make 
sound  and  quick  decisions  when  SAV  requests 
occur.  Security  awareness  is  also  an  important 
part  of  the  program.  DTIRP  will  publish  DIS  In¬ 
dustrial  Security  Letter  articles  such  as  this  one, 
and  sponsor  training  for  DIS  Industrial  Security 
Representatives.  In  fact,  the  person  on  the  cutting 
edge  for  the  DTIRP  is  the  DIS  representative  in  the 
field.  Armed  with  trairung  and  an  understaruiing 
of  the  arms  control  process,  he  or  she  will  be  able 
to  provide  information  and  assistance  and  to 
gather  data  to  support  DTIRP  planning  in  the 
event  a  Special  Access  Visit  is  requested  and  ap¬ 
proved.  Knowledge,  planrting  and  timely  prepara¬ 
tion  have  proven  te)rs  to  success  in  arms  control 
treaty  implementation  in  the  past.  The  DTIRP  is 
worl^g  to  maintain  the  lead  in  assisting  organiza¬ 
tions  in  protecting  their  equities  which  are  impor¬ 
tant  to  our  national  security. 

What  should  you  be  doing  now? 

The  information  provided  in  this  article  is  for 
the  edification  of  security  professiotuds  in  industry 
and  goverrunent  whose  facilities  nuiy  be  subject  to 
future  treaty  inspections.  While  no  immediate  ac¬ 
tion  is  required,  it  is  not  too  early  to  start  thmking 
about  the  security  implicatiorw  of  these  inspec¬ 
tions.  For  more  irdormation  on  DTIRP  activities 
you  can  contact  the  program  manager  Chief,  Of¬ 
fice  of  Security,  On-Site  Inspection  AgeiKy,  at 
1-800-283-2179. 


Seatritif  Awareiu$s  Bulletin 


22 


Number  4-92 


Security  Penguin  Contest 

By  Art  Fa jans,  formerly  Director  of  Defense  Security  Programs 
Office  rff  Secretary  of  Defense 

I  hope  you  have  had  some  fun  with  this.  I 
know  I  have.  The  response  was  very  positive. 

Over  90  entrees  were  submitted  and  that  has  made 
the  selection  of  winners  that  more  difficult.  1  like 
to  think  that  everyone  is  a  winner  and  that 
thoughtful  approaches  to  effective  security  aware¬ 
ness  that  the  contest  may  have  engendered  can  be 
used  locally  at  your  activities,  facilities,  and  or¬ 
ganizations. 

Not  everyone  is  a  fan  of  the  security  penguin, 
but  I  knew  that  before  the  contest  was  launched. 

One  entry  even  suggested  calling  the  penguin 
"STOOPID,"  but  I  was  heartened  by  the  fact  that 
only  three  negative  responses  to  the  penguin  were 
received. 

This  is  one  instance  where  1  will  not  call  for 
uniform  implementation.  The  security  penguin  is 
not  regulatory  by  any  stretch  of  the  imagination 
and  whether  you  find  it  useful  for  your  own 
programs  or  not,  is  entirely  up  to  you. 

Someone  also  sent  me  a  copy  of  a  USA  Today 
article  on  penguins  entitled,  "Penguins  are  not  as 
polite  as  their  tuxedos  might  suggest."  One  quote 
from  the  article  sums  up  my  view  of  the  penguin 
very  well.  "They  are  strong,  tough,  aggressive 
animals  in  a  tough,  harsh  environment,  and  cute 
just  does  not  apply."  1  can  also  relate  to  another 
definition  of  what  a  penguin  represents — flippant 
dignity. 


“Good  Job  perfonnance  and  lax  security  are  poles  apart” 


Trusty 


A  security  professional's  work  holds  particular 
importance  to  the  environment  in  which  that  work 
is  accomplished.  Not  only  does  that  work  strive  to 
protect  the  organization's  infrastructure,  opera¬ 
tions,  activities,  and  systems,  it  must  also  be  a 
good  barometer  of  change.  As  a  result  of  rapid 
and  radical  world  geopolitical  events  including  the 
break-up  of  the  former  Soviet  Union  and  Warsaw 
Pact,  security  must  be  more  flexible,  efficient,  and 
cost  effective.  We  must  recognize  that  changes  in 
the  threat  as  well  as  other  challenging  issues  of  af¬ 
fordability,  risk,  vulnerability  and  the  value  of  in¬ 
formation,  systems,  or  technology  will  directly  af¬ 
fect  how  security  requirements  will  be  defined  and 
implemented  in  the  future.  To  meet  these  challen¬ 
ges  we  will  need  security  professionals  who  are 
strong,  tough,  aggressive  people  who  can  operate 
in  a  tough,  harsh  environment — cute  just  does  not 
apply. 

Another  entry  suggested  that  some  of  the 
slogan  entries  be  shared  so  that  the  whole  com¬ 
munity  might  benefit  from  other  ideas.  Here  are  a 
few  representative  entries: 


Think  Security.  Don't  put  US  on  thin  ice 
Security  is  a  breeze,  if  you  remember  security  A-B-C’s 
secURity— together  we  can  do  iti 
Without  your  help — security  will  be  out  in  the  cold 
Keep  your  cool-Security  is  the  rule 

The  Cold  War  may  be  over  but  that's  no  reason  to  put  a  freeze  on  security 

Don '.  let  your  secrets  slip  away 
Avoid  thin  ice  in  your  security  program 
Security  violations  melt  my  cool 


Number  4-92 


23 


Security  Awareness  Bulletin 


Security  is  like  an  iceberg,  you  only  see  the  tip 
World  relations  may  be  warming,  but  don't  put  security  on  ice 
Security  is  a  warm  feeling 
Security  will  never  leave  you  in  the  cold 
Keep  your  cool  when  handling  classified  information 
Don't  let  security  violations  snowball — report  them 
Security  is  like  a  thermometer— let's  PROTECT  its  degree  by  AWARENESS  at  all  times 
Spies  and  Traitors  wind  up  in  the  cooler,  don't  skate  on  thin  ice  PROTECT  OUR  NATIONS 

SECRETS 

Better  button  up  your  secrets 

The  cold  war  may  be  over,  but  without  security— it  could  get  very  hot 

AND  NOW  THE  MOMENT  OF  TRUTH.  The 
winners  are: 

For  naming  the  penguin:  For  the  slogan: 

Trusty  Good  Job  Performance  And  Lax 

Security  Are  Poles  Apart 

D.  Wilmer  Rivers,  Jr. 

Teledyne  Geotech 
Alexandria,  Virginia 


David  A.  Davenport 
Johnson  Space  Center 
Houston,  Texas 


Security  Awareness  Bulletin 


24 


Number  4-92 


Security  Penguin  —  The  Final  Chapter? 


The  preceding  article  by  Art  Fajans  provides 
some  insight  into  Art's  thinking  when  he 
originated  the  idea  of  a  security  logo  or  mascot  in 
the  form  of  a  penguin  and  sponsored  a  contest  to 
name  the  bird  and  come  up  with  a  slogan.  Need¬ 
less  to  say.  Art  got  a  lot  of  good-natured  ribbing 
from  all  quarters  on  his  "penguin  thing,"  which 
culminated  with  his  retirement  in  April  1992. 

At  his  retiremen'.  luncheon  he  was  presented 
with  a  lot  of  penguin  memorabilia,  including  an 
item  depicted  in  the  accompanying  photo.  Ap¬ 
propriately,  the  final  presentation  was  a  rendering 
of  Trusty's  tombstone,  with  an  appropriate  epitaph. 


Art  denied  the  "passing"  of  Trusty  and 
adamantly  asserted  his  continued  existence.  And 
he  may  be  right.  While  "Trusty"  does  not  exist  as 
an  "official"  logo,  it's  just  possible  that  reported 
sightings  of  the  friendly  bird  (like  Elvis)  may  sur¬ 
face  from  time  to  time  in  the  future. 

Time  will  tell . . . 

For  those  of  you  who  wish  to  adopt  Trusty  to 
promote  your  security  programs,  please  ask  us  for 
the  artwork  and  we  will  provide  you  with  a  copy. 


Number  4-92 


25 


Security  Awareness  Bulletin 


A  Clearinghouse  for  Security  Education  Products 


A  couple  of  Bulletins  ago  we  ran  the  following  announcement  and  got  a  good  response. 

We're  running  it  again  in  case  we  missed  you  the  first  time. 

When  it's  time  for  you  to  give  a  security  briefing,  does  the  availability  of  training  materials 
remind  you  of  Mother  Hubbard's  cupboard?  When  presenting  security  briefings,  have  you  ever 
felt  that  you  and  the  flight  attendant  addressing  a  plane  full  of  frequent  flyers  have  a  lot  in  com¬ 
mon?  Whether  you  are  a  security  novice  and  know  no  sources  for  security  education  materials 
or  a  security  expert  but  know  only  the  same  old  sources,  a  Security  Education  Project  is  under¬ 
way  in  an  effort  to  help. 

The  Joint  Industry/Govermnent  Security  Awareness  Group  (JIGSAG)  is  supporting  the 
Department  of  Defense  Security  Institute's  efforts  in  setting  up  a  clearinghouse  for  security 
education  materials.  The  idea  is  to  have  a  central  point  to  send  products  that  have  proven  them¬ 
selves  effective — in  other  words,  that  your  audience  likes — so  that,  with  everyone  sharing 
products,  you  suddenly  have  a  tremendous  pool  of  resources  to  draw  from. 

The  products  initially  targeted  for  collection  are  videotapes  and  PC-based  tutorials/briefmgs. 

The  members  of  the  Project  encourage  your  participation  and  ask  that  you  forward  your 
product  to: 

Ronald  Thinnes 
Attn;  JIGSAG  Video  Review 
BTG.  Inc. 

1945  Old  Gallows  Rd. 

Vienna,  VA  22182 
(703)  761-6517 
fax:  (703)  556-9290 


All  products  will  be  evaluated  by  JIGSAG  for  accuracy,  quality,  propriety  in  accordance 
with  defined  standards,  and  applicability  within  the  DOD/Industrial  Security  communities. 

The  committee  will  also  send  a  description  of  every  product  to  the  DODSI  along  with  the  evalua¬ 
tion  results.  An  example  is  provided  on  the  next  page.  EXDDSI  will  have  the  best  ones 
reproduced  and  distributed  either  through  the  DIS  Education  and  Training  Specialists  (for  loan) 
or  through  inexpensive  commercial  distribution  centers  (for  purchase — $20-30).  DODSI  will 
also  publish  a  catalog  of  all  submitted  training  materials,  similar  to  what  is  provided  in  its 
"Training  Aids  for  Security  Education." 

Don't  be  reticent.  Even  if  your  video  hasn't  won  an  Oscar,  it's  a  "go"  for  entry  in  the  catalog 
and  may  be  a  good  candidate  for  distribution.  Why  don't  you  take  a  minute  to  rummage 
through  your  cabinets  for  any  training  products  you've  put  together.  They  don't  have  to  be 
stellar  acts — their  novelty  and  availability  are  important  factors,  too. 


j*6»»CMrHv 

IBiteufltf  V>4«o  IX 

"L 


With  your  help,  this  could  turn  out  to  be  a  great  success! 


Security  A  wareness  Bulletin 


26 


Number  4-92 


Product  Profile 


Product  Name;  . Jonathan  Pollard — A  Portrayal 

Product  Type: . Videotape 

Subject  Focus: . Espionage 

Production  date: . 1991 

Produced  by: . Defense  Intelligence  Agency 

ClassificationA^imitations:  . Unclassified 

Availability  data: . copies  available  from  FilmComm 

Charge  for  copies:  . approx.  $20-30  depending  on  tape  size  and  mode  of  delivery 


Videotape  Data 

format:  . 1/2"  or  3/4"  Rvmning  Time:  18:00 


General  Assessment 


Applicability: . 

Propriety: . 

Technical  accuracy: . 

Geographic  limitations: . 

Currency  and  durability: . 

Production  quality: . 

Interest:  . 

Strength  and  clarity  of  message: 

Tone  and  impression: . 

Use  of  time: . 

Flexibility: . 

Prerequisite  knowledge:  . 

Orientation: . 

Credibility: . 


.  suitable  for  all 

.  no  propriety  problems  noted 

.  generally  accurate 

.  not  geographically  limited 

.  current  and  having  an  indefinite  life-span 

.  high  quality  production 

.  able  to  hold  attention  well 

.  the  message  is  strong  and  clear 

.  generally  positive  and  constructive 

.  length  and  pacing  are  on  target 

.  could  be  tailored  easily 

.  minor  presumptions  about  knowledge 

.  suitable  for  all  audiences 

.  high  degree  of  realism  and  credibility 


Description  and  Evaluation: 

Jonathan  Pollard  was  an  employee  of  the  Navy,  but  because  of  his  position  as  a  counterintelligence 
analyst,  he  had  access  to  hundreds  of  classified  documents  from  the  intelligence  departments  of  many 
federal  agencies — and  at  the  time  of  his  arrest,  had  stuffed  enough  of  these  documents  in  his  apartment  to 
fill  a  space  10'  x  6'  x  4'.  Pollard  is  an  American  who  spied  for  Israel.  He  is  serving  a  life  sentence  for  his 
espionage  work.  And  the  reason  he  is,  is  thanks  in  part  to  an  observant  co-worker  who  noticed  suspi¬ 
cious  activity  and  was  smart  enough  to  report  it.  This  video  reenacts  the  events  at  Naval  Intelligence 
Command  in  Suitland,  Maryland,  that  led  to  the  realization  Pollard  was  involved  in  more  than  just  doing 
his  job. 


Number  4-92 


27 


Security  Awareness  Bulletin 


A  New  Crowd  Phaser  at  DoDSI! 

The  first  Advanced  Industrial  Security  Management  Course  (aismc) 

will  be  taught  at  the  DoD  Security  Institute 
from  November  17-19, 1992,  in  Richmond, 

Virginia.  This  course  for  defense  contractor 
personnel  goes  beyond  the  ever-popular 
Industrial  Security  Management  Course  to 
emphasize  specific  requirements  and 
administrative  procedures  in  safeguarding  clas¬ 
sified  defense  information .  'r  possessing 
facilities. 

Some  of  the  topics  to  be  presented: 

■  International  Aspects 

■  Independent  Research  and  Development 

■  STU-III 

■  Programmatic  Inspections 

■  AIS  Security 

■  Alarms 

■  Technology  Transfer 

Assisting  the  DoDSI  faculty  will  be  Department  of  Defense  specialists  offering  unique 
insight  into  particular  programs. 

This  first  AISMC  class  is  by  invitation  only,  including  many  attendees  who,  we  hope, 
will  provide  us  comment  and  feedback  with  an  eye  toward  making  the  course  more 
usable.  Consequently,  there  are  no  vacancies  in  the  November  course.  However,  we 
encourage  you  to  sign  up  for  one  of  the  dates  offered  below  during  FY  93: 

March  30  -  April  1, 1993 

June  15  - 17, 1993 

August  31  -  September  2, 1993 

The  prerequisites.  To  attend  the  AISMC  you: 

✓  must  have  been  involved  with  the  Defense  Industrial  Security  Program  for  at  least 
three  years. 

✓  must  have  successfully  completed  the  Essentials  of  Industrial  Security  Management 
and  Protecting  Secret  and  Confidential  Documents  independent  study  courses. 

✓  should  also  have  successfully  completed  the  Industrial  Security  Management 
Course. 

For  additional  information  about  registering,  please  call  the  DoDSI  Registrar's  Office 
at  (804)  279-4891. 


Security  Awareness  Bulletin 


28 


Number  4-92 


WHArSSPINAFTER 

Since  its  purpose  is  to  "spread  the  word"  on  how  we 
can  improve  what  we  do  in  security  implementation, 
SPIN  is  looking  for  successes  or  solid  ideas  on 
making  improvements.  It's  after  the  small  improve¬ 
ments  in  day-to-day  operations  as  well  as  the  "super- 
colossal"  changes  and  everything  in-between. 
(Don't  keep  the  small  improvements  to  yourself! 
When  you  multiply  those  times  the  number  of  loca¬ 


tions  that  could  use  them,  the  benefits  can  rival  or 
Made  improvements  to  your  security  program?  ^^ceed  the  value  of  the  "super-colossal.")  SPIN 
Added  some  nifty  features  to  help  you  meet  your  to  about: 

security  reqviirements  better  or  with  less  resoiuces? 


Want  to  know  what  others  have  done,  are  doing  or  ,  Successes  in  getting  better  results  in  applying 
thinking  about  that  you  could  use  to  do  a  better  security  program  requirements  that  others 

security  job?  can  try.  Those  may  come  from  greater  effective- 


You're  in  luck.  DoD  has  set  up  a  program  to  capture 
and  share  that  information.  It's  called  the  Security 
Program  Improvement  Network,  a  long  enough  title  for 
us  to  call  it  "SPIN"  for  short. 


ness  or  resource  savings  while  still  meeting  the 
requirements.  They  should  be  ones  that  have  a 
wide  application  in  your  component,  within 
DoD  or  among  DoD  contractors.  They  may  be 
in: 


WHYSPIN 

The  security  pros  in  DoD  and  its  contractors  and  our 
cormterintelligence  folks  know  that  getting  the 
security  job  done  right  is  more  than  just  doing  what 
you  have  to  do.  And,  if  one  of  them  has  found  a 
better  way,  you  can  bet  that  there  are  plenty  of  others 
who  would  want  to  adopt  it.  SPIN  is  the  link  be¬ 
tween  those  with  tried  and  effective  solutions  and 
those  still  looking  for  them. 

By  bringing  the  two  together,  one's  success  becomes 
success  for  all.  If  we  really  get  good  at  sharing  these 
solutions,  think  what  it  will  mean  for  the  strength  of 
our  security  programs  and  the  wise  use  of  our 
security  resources. 

But  SPIN'S  not  just  limited  to  the  pros.  DoD  has  that 
whole  range  of  cleared  people  in  its  activities  and 
contractors  who  work  under  our  security  programs 
day-in  and  day-out.  They've  been  a  continuing 
source  of  good  ideas  that  have  led  to  improving  what 
we  do  in  security.  After  all,  the/re  the  people  who 
have  the  most  influence  on  whether  security  does  or 
doesn't  work. 


»  how  you  operate  the  programs,  the  proce¬ 
dures  you  have  introduced,  the  way  you 
have  organized,  what  you  have  done  to 
motivate  security  support; 

>»  your  approach  to  assistance  and  inspection, 
how  you've  established  the  value  of  security, 
how  you've  handled  continuous  evaluation 
of  cleared  personnel, 

»  the  equipment  you  use,  the  software  you 
have  created  or  applied,  how  you've  over¬ 
come  a  problem  inherent  in  the  require¬ 
ments,  etc. 

Ideas  on  making  improvements  you've  been 
thinking  about  in  meeting  the  security  require¬ 
ments.  SPIN  can  get  you  some  feedback  from 
others  who  may  have  already  implemented  or 
tried  those  ideas  or  might  help  you  bring  them 
about. 

Articles,  books,  other  publications,  or  software 
you  have  foimd  particularly  helpful  in  improv¬ 
ing  your  security  operation. 


Ntunbcr4'92 


29 


Securitjf  Awartness  Bulletin 


SPIN  is  concerned  with  doing  better  what  we  are  the  contribution  unless  you  tell  us  you'd  prefer  to 
asked  to  do  rather  than  with  changes  in  program  receive  it  directly, 
requirements.  That's  not  because  it  discourages 

change;  it'sjust  that  we  need  to  keep  it  focused  to  get  Formally  published  submissions  will  identify  the 
the  most  benefit  from  it.  (The  Institute  hopes  to  begin  submitters  in  the  byline  unless  anonymity  has  been 
a  separate  publication  that  will  give  you  a  way  to  requested.  The  SPIN  Coordinator  and  Committee 
share  your  thoughts  on  program  changes.)  will  review  those  each  year  to  select  the  ones  they 

recommend  for  special  recognition.  They'll  refer 
HOW  SPIN  WORKS  them  to  the  Deputy  Assistant  Secretary  of  Defense 

(Counterintelligence  and  Security  Counter- 
SPIN  Coordinator  and  Committee  measures)  for  a  personal  thanks  for  the  contribution 

and  a  special  certificate.  We'll  also  announce  the  top 
DoDSI's  SPIN  Coordinator  will  receive  your  submis-  Spinners  in  the  Bulletin. 
sions,  refer  them  as  needed  for  review  by  volunteer 
SPIN  comnuttee  members  from  DoD  and  DoD's  con-  TAKING  PART 
tractors,  work  with  you  to  prepare  them  for  publica¬ 
tion,  and  make  sure  you  are  recognized  for  your  How  do  you  share  your  successes  and  ideas  in  doing 
participation.  the  security  job  better?  It's  quite  easy. 


The  SPIN  committee  will  aid  the  Coordinator  in 
selecting  submissions  for  publication  and  for  special 
recognition  and  in  deciding  added  information  that 
would  be  useful. 

Publication 

Selected  submissions  will  appear  in  the  DoDSI 
Security  Awareness  Bulletin.  As  the  number  warrants, 
we'll  look  to  publishing  special  editions  of  the  Bul¬ 
letin  on  SPIN  or  to  producing  a  separate  SPIN  publi¬ 
cation. 

DoDSI  will  separately  publish  submissions  that  have 
restricted  dissemination.  We're  also  exploring 
having  SPIN  as  well  as  DoDSI  and  other  material 
available  to  you  on  an  electronic  bulletin  board. 
(More  on  that  in  a  subsequent  Security  Awareness 
Bulletin). 

Periodically,  we'll  put  together  the  other  submis¬ 
sions  for  separate  distribution  as  a  "grab  bag"  of 
ideas  and  actions  that  may  help.  For  materials  that 
may  be  generally  useful,  we'll  announce  how  copies 
can  be  obtained. 

Recognition 

Besides  the  good  feeling  from  sharing  your  successes 
and  ideas  with  others  and  knowing  you're  helping 
improve  security,  SPIN  wants  to  give  you  special 
recognition.  After  all,  it's  your  time  and  effort! 

So,  look  for  a  Certificate  of  SPIN  Participation  that 
we'll  send  to  each  submitter.  That  will  come  through 
your  command  or  company  commending  you  for 


•  For  your  successes,  just  describe  the  problem  or 
situation  involved,  what  you  did  to  make  the 
improvements,  how  you  did  it,  what  difficulties 
you  had,  if  any,  in  doing  it  and  how  you  over¬ 
came  them. 

•  For  ideas  you  want  to  "test"  with  others,  just 
relate  what  it  is,  why  you  think  it  will  help,  and 
how  it  would  work. 

For  publications  and  software,  send  your 
description  of  their  value  and  application.  If  you 
don't  include  them,  you'll  need  to  say  where 
they  can  be  obtained  and  identify  the  author, 
title,  etc.  If  you  send  software,  include  a  brief 
description  of  what  it  does,  how  to  use  it,  and 
any  conditions  for  its  release  to  others. 

Be  as  detailed  as  need  be  and  include  a  cite  of  any 
related  regulation  portions  that  apply. 

If  your  submission  is  classified,  limit  it  to  no 
higher  than  Secret  and  make  sure  you've  got  it 
correctly  portion  marked. 

Submit  your  contribution  in  typed  form  and,  if 
you  can,  include  a  copy  on  floppy  diskette  (5.25 
or  3.5  inches)  in  a  DOS  program.  Make  sure  you: 

»  Include  your  name,  organization,  com¬ 
ponent  or  company,  mailing  address,  and 
telephone  number  (commercial  and,  where 
available,  DSN  numbers). 


Security  Awareness  Bulletin 


30 


Number  4-92 


»  Tell  US  if  you  want  your  luune,  organization  Send  them  to: 
or  component  or  company  identihed  in 
reviewing  or  publishing  your  contribution.  DoD  Security  Institute 

ATTN:  SMD(SPIN  Coordinator) 

>»  Include  any  restrictions  that  you  know  of  c/o  DGSC 

and  the  authority  on  releasing  its  content  to  8000  Jeff  Davis  Highway 
other  federd  agencies  and  personnel,  to  con-  Richmond,  VA  23297-^1 
tractors,  or  to  the  public. 

For  assistance  or  more  information,  contact  the  SPIN 
Coordinator,  Carl  Roper,  at  the  above  address  or  by 
telephone  at  (804)  279-5593  or  DSN  695-5593.  Carl 
has  the  DoDSI  flyer  on  SPIN  which  he  can  send  to 
you. 

Put  out  the  word  to  your  organizations  and  personnel  and 
encourage  their  participation.  SPIN  starts  the  moment  we 
have  the  first  submission.  Join  in  now! 


New  Videos . . . 

Briefing  the  Susceptible  Traveler 


Date:  1991  Lengdi:  11:44  min.  Medium:  1/2" 

Order  from:  Pro  Star  International 
P.O.Box  21526 
Salt  Lake  City,  UT  84121 
1-800-775-0761 
fax:  (801)943-5178 

Summary:  A  brief-the-briefer  video  for  security  managers 
who  need  to  brief  employees  traveling  outside  the  U.S. 
Produced  by  Northrop  Corporation  in  conjunction  with 
the  FBI's  Susceptible  Traveler  Program.  Qosed  capticmed 
for  dre  hearing  impaired. 


NORTHROP 


Foreign  Travel  Briefing  — 
Don’t  Leave  Home  Without  It 

Date  1991  Length:  7:10  min.  Medium:  1/2" 


NORTHROP 


Order  from:  Pro  Star  International 

P.O.  Box  21526 
Salt  Lake  City,  UT  84121 
1-800-775-0761 
fax:  (801)943-5178 


Summary:  Designed  to  be  viewed  by  the  average  employee  traveling  to  a  foreign  country.  Produced  by 
Northrop  Corporation.  Closed  captioned  for  the  hearing  impaired. 


Number  4-92 


31 


Security  Awareness  Bulletin 


ANNOUNCING... 


Basic  Personnel  Security  Investigations 
Resident  Course 

In  response  to  requests  for  training  in  basic  personnel  security  investigations  from 
various  security  organizations,  the  DoDSI  will  offer  a  two-week  basic  PSI  Course  in  FY  1993  to 
be  held  at  DoDSI,  Richmond,  VA. 

January  25  -  February  5, 1993 

To  be  eligible  for  attendance  at  this  course,  you  must  be  a  Federal  employee  performing 
in  a  security-related  function,  e.g.  investigator,  investigative  technician,  personnel  security 
specialists,  etc.  The  course  covers  generd  aspects  of  personnel  security  investigations.  Tlie  first 
week  of  the  course  addresses  various  procedures  and  techniques  for  record  reviews  and 
interviews,  development  and  resolution  of  security  issues  and  fundamental  report  writing. 
Attendees  participate  in  several  practical  exercises  to  use  their  interviewing  and  record  reviewing 
skills.  The  second  week  of  the  course  is  designed  for  those  individuals  that  are  responsible  for 
also  conducting  various  types  of  subject  interviews  in  personnel  security.  Emphasis  is  placed  on 
learning  skills  in  subject  interviewing  through  a  series  of  practical  and  criteria  exercises. 
Individuals  that  do  not  conduct  subject  interviews  may  elect  to  attend  only  the  first  week  of  this 
course.  The  second  week  is  limited  to  those  who  are  required  to  conduct  Subject  Interviews  as 
part  of  their  job.  You  should  indicate  which  learning  track  is  appropriate  for  you  when  applying 
for  attendance. 

Fill  out  the  attached  form  and  mail  it  to  the  Registrar's  Office  at  the  Department  of 
Defense  Security  Institute,  c/o  DGSC,  8000  Jefferson  Davis  Highway,  Richmond,  VA  23297- 
5091.  For  course  information,  call  the  Personnel  Security  Investigations  Department  (804)  279- 
4179  or  AVN  695-4179. 


Complete,  detach  and  return 

Bteagg  Print 

Your  Name 

MAIL  TO:  Registrar,  DoDefense  Security  Institute,  8000  Jeff  Davis  Hwy.,  Ric)unond,VA  23297-5091 

Title 

SSN 

Agency  Name 

Address 

Telephone 

Supervisor 

Course  Title 

Course  Dates 

First  Week  Onlv:G  Two  Weeks:  □ 

Seairit}/  Awarenes$  Bulletin 


32 


Number  4-92 


Industrial  Security  —  Customized 


To  help  both  you  and  the  already  overworked  Industrial  Security  Rep,  the  Industrial 
Security  Department  faculty  at  DoDSI  now  has  a  one-  to  two-day  training  session  (for 
government  and  industry)  that  covers  industrial  security  subjects  you  can  tailor  to  your 
specific  needs.  For  example,  do  you  have  numerous  Document  Control  personnel  who 
need  training  in  accountability,  reproduction,  destruction?  We  can  help.  You  work 
with  us  in  the  design.  You  pick  the  site;  no  cost  other  than  travel,  food,  and  lodging  for 
one  or  two  instructors. 

For  more  details  about  this  offer,  please  call  either  Wayne  Lund  or  Michael  Black  at 
(804)  279-5257  (DSN  695-5257). 


New  Videos  . . . 

The  Interagency  OPSEC  Support  Staff  has  just  released  two  new  videotapes  to  the  OPSEC  community. 
The  tapes  had  their  "world  premier"  at  the  National  OPSEC  Conference..  Videos  are  no  cost. 

Order  from:  lOSS 

Attn:  Publications  Department 
6411  Ivy  Lane  Ste  400 
Greenbelt,  MD  20770-1405 

Applying  OPSEC  in  R&D  Activity 

Date:  1992  Length:  16  min. 

Summary;  Discusses  the  role  of  OPSEC  in  protecting  sensitive 
information,  especially  at  test  ranges.  It  is  an  edited  version  of  a  briefing  originally  presented  to  the 
Strategic  Defense  Initiative  Organization. 

OPSEC:  Protecting  Our  Edge 

Date:  1992  Length:  9  min. 

Summary:  Explains  how  OPSEC  can  help  protect  sensitive  technological  and  economic  information  from 
loss  to  foreign  competitors.  Produced  by  the  Defense  Information  Systems  Agency. 


Number  4-92 


33 


Security  Awareness  Bulletin 


New  Video . . . 

Safes,  Locks,  and  Videotapes 


Date:  1991 
Order 


or 


Length:  12  min.  Medium:  VC  1/2"  or  3/4" 

FilmComm 

641  North  Avenue 

Glendale  Heights,  IL  60139 

(708)790-3300 

fax:(708)790-3325 

Pro  Star  International 

P.O.Box  21526 

Salt  Lake  City,  UT  84121 

1-800-775-0761 

fax:  (801)943-5178 


Summary:  This  video  talks  about  the  different  GSA  containers  and  locks;  container  labels,  how  to 
inspect  a  container  and  lock.  How  to  change  a  combmation.  Lists  security  device  manufacturers.  Comes 
wiA  pamphlet  that  provides  additional  information.  Produced  by  the  Defense  Security  Institute. 


New  Video . . . 


Friend  and/or  Foe,  The  New  Espionage  Chaiienge 


Date:  1991 
Order  froiiu 


or 


Length:  20  min.  Medium: VC 

Pro  Star  International 
P.O.Box  21526 
Salt  Lake  City,  UT 
1-800-775-0761 
fax:  (801)943-5:78 

FilmCorrun 
641  North  Avenue 
Glendale  Heights,  IL  60139 
(708)  790-3300 
fax:(708)790-3325 


Summary:  An  up-to-date  film  on  the  changing  threat  to  national  security  showing  that  our  international 
firiends  are  sometimes  our  foes.  When  any  coimtry's  need  or  desire  for  our  technology  spurs  them  to 
illegally  acquire  non-exportable  U.S.  technology,  it  has  passed  from  friend  to  adversary.  And  attempts 
are  being  made  all  the  time.  The  cooperation  among  U.S.  Customs,  American  industry,  and  the  FBI  is 
helping  to  curb  the  increasing  flow  of  illegal  export.  This  20-iTunute  film  clearly  states  the  enormity  of  the 
problem  and  what  you  can  do  to  help  prevent  further  loss  of  our  nation's  top  security  priority:  its 
competitive  edge  in  world  technology.  Produced  by  Hughes  Corporation  in  cooperation  wi^  the  FBI 
and  U.S.  Customs.  Pro  Star  International  also  has  a  closed  captioned  version  for  the  hecuing  impaired. 


Security  AuMrtne$$  Bulletin 


34 


Number  4-92 


New  Video . . . 

Is  Your  PC  Data  Safe? 

Date:  1992  Length:  21  min.  Cost:  $325.00 

15-day  preview  fee:  $27.50  (includes  shipping/handling) 

Order  fronu  Pro  Star  International 
P.O.  Box  21526 
Salt  Lake  City,  UT  84121 
1-800-775-0761 
fax:(801)943-5178 

Summary:  This  computer  security  training  program  for 
government  contractors  comes  with  a  21-minute  video, 
instructor's  manual,  and  student  guide  materials.  Video 
shows  the  importance  of  following  the  guidelines  in 
Section  8  of  the  Industrial  Security  Manual,  and  your 
SPP.  Dramatization  tells  the  story  of  a  new  company 

president  with  a  poor  security  posture  and  the  tips  he  •  j  u  n 

receives  from  his  ghosUy  coUeague.  Video  is  closed  captioned  for  hearing  impaired.  Produced  by  Pro 
Star  International.  Program  also  comes  in  a  second  version:  protecting  trade  secrets  and  proprietary 
information. 


Deliver! 

The  Security  Management  Department 
at  the  DoD  Security  Institute  has  written 
an  easy-to-follow  pamphlet  called 
Deliver!  that  answers  your  questions  on 
transmitting  and  transporting  classified 
materials.  To  order,  see  form  on  last 
page  of  this  Bulletin. 


Number  442 


35 


Security  Axearmeu  Bulletin 


Security  Awareness  Bulletin 


36 


Number  4-92 


Security  Awareness  Publications  Available  From  The  Institute 


Postage  Requirement:  \Nq  ask  that  you  provide  postage,  but  the  publications  are  free  of  charge.  Instructions  for 
figuring  postage  are  provided  on  the  next  page.  See  ordering  instructions  below. 

To  Order:  1 .  Check  publications  on  the  list  below. 

2.  Add  total  weight.  Include  1  oz.  for  envelope. 

3.  Figure  the  postage  using  information  on  the  next  page. 

4.  Choose  envelope  size  (see  chart  4,  next  page);  affix  postage  and  mailing  label. 

5.  Send  this  page  with  stamped  (no  checks,  please),  self-addressed  envelope  to; 

DoD  Security  Institute 
Attn:  EPD 
do  DGSC 

Richmond,  VA  23297-5091 

(804)  279-5314/4223  or  DSN  695-5314/4223 


(TAS)  Training  Aids  for  Security  Education.  June  1 992.  Catalog  of  audiovisual  and  printed 

material  of  interest  to  security  educators.  Instructions  for  ordering . . 3.5  oz. 

(REC)  Recent  Espionage  Cases:  Summaries  and  Sources.  September  1991.  Seventy-eight  cases, 

1975  through  1989.  Thumb-nail"  summaries  and  open-source  citations . . 3.5  oz. 

(FIT)  The  Foreign  Intelligence  Threat  to  U.S.  Defense  Industry.  By  Defense  Security  Institute 

staff.  January  1991 . . 3.0  oz. 

(FTB)  Foreign  Travel  Briefing.  1981 .  Script  of  briefing  designed  for  cleared  employees  traveling  to 

designated  countries.  Outlines  methods  used  by  hostile  intelligence  services  and  precautions  against 

them.  (For  14-minute  tape/slide  briefing,  see  Training  Aids  for  Security  Education.")  . . 2.5  oz. 

(SIT)  Soviet  Intelligence  Targeting  of  the  US  Scientific  Community,  August  1990.  A  basic  tutorial  for 

those  in  contact  with  the  Soviet  scientific  community . . 3.0  oz. 

(CUT)  Control  of  Unclassified  Technical  Data  with  Military  or  Space  Application,  May  1985. 

DoD  5230.25-PH.  20-page  booklet  prepared  by  the  Office  of  Secretary  of  Defense  explaining  the 

DoD  program  to  limit  public  disclosure  of  export-controlled  technical  data  and  the  special  markings 

for  technical  documents . . 1.5  oz. 

(SAM)  Soviet  Acquisition  of  Militarily  Significant  Western  Technology:  An  Update,  September 

1985.  Western  products  and  technology  secrets  are  being  systematically  acquired  by  intricately 

organized,  highly  effective  collection  programs . . 5.5  oz. 

DELIVERI  A  pamphlet  on  how  to  transmit  and  transport  your  classified  materials . . 1 .0  oz. 


Individual  back  issues  of  the  Security  Awareness  Bulletin  through  #2-89  are  no  longer  available  from  the  In¬ 

stitute.  Reprints  of  past  feature  articles  have  been  brought  together  under  a  single  cover  in  a  publication.  Security 
Awareness  in  the  1980s.  Available  from  the  Government  Printing  Office,  stock  number  008-047-00394-3.  Price  is 


$1 1 .00.  To  order  call  (202)  783-3238. 

Security  Awareness  Bulletin.  Back  issues  available  from  the  Institute; 

(1-90)  Oct  89  Foreign  Travel.  FOR  OFFICIAL  USE  ONLY . 3.0  oz. 

(2-90)  Jan  90  The  Case  of  Randy  Miles  Jeffries  . 3.0  oz. 

(3-90)  Apr  90  Beyond  Compliance  -  Achieving  Excellence  in  Industrial  Security  . 5.5  oz. 

(4-90)  Aug  90  Foreign  Intelligence  Threat  for  the  1 990s  3.5  oz. 

(1-91)  Jan  91  Regional  Cooperation  for  Security  Education  . 3.5  oz. 

(2-91)  Sep  91  AIS  Security . 3.5  oz. 

(1-92)  Oct  91  Economic  Espionage . 3.5  oz. 

(2-92)  Feb  92  Self-Inspection  Handbook  . 4.0  oz. 

(3-92)  Mar  92  OPSEC . 2.5  oz. 

Allow  for  envelope  .  /  1 .0  oz. 

Total  weight  . . 

Send  postage  in  the  amount  of . $ _ 


Number  4-92 


37 


Security  Aioareness  Bulletin 


Postage  Information 


If  total  weight  is  11  ounces  or  less; 

Chart  1 :  find  the  amount  of  postage 
Example;  If  total  weight  is  4.5  oz.,  postage  is  S  1.21. 


Chart  1 

Weight  not 

exceeding; 

First  Class  Rate 

1  oz.  .  . 

. $0.29 

2  oz.  .  . 

. 0.52 

3  oz. 

. 0.75 

4  oz. 

. 0.98 

5  oz. 

. 1.21 

6oz.  . 

. 1.44 

7oz.  .  . 

. 1.67 

8oz.  .  . 

. 1.90 

9  oz.  .  . 

. 2.13 

lOoz. 

. 2.36 

11  oz.  .  . 

. 2.59 

Chart  4 

Envelope  Size 

Publications  measure  81/2x11” 

No.  of  pubs 

envelope 

1-9  .  .  . 

. 9  1/2  X  12” 

10-18  . 

. 10  X  15” 

If  total  weight  is  greater  than  11  ounces: 
Chart  2:  find  postal  /one  using  first  3  digits  of  your 
ZIP  code 

Chart  3;  determine  amount  of  postage  using  weight 
and  zone 


Chart  2 

Postal  Zone  Chart 

1 

2iP  Coda 

PrtttiKM  Zone 

Zip  Coda 
Prefnta* 

Zone 

ZIP  Code 

Pfef-«es  Zone 

004  005 

3 

295 

3 

513-560 

5 

006-009 

7 

296 

4 

561-576 

6 

010-043 

4 

297 

3 

577 

7 

044 

5 

296  322 

4 

580  585 

6 

045 

4 

323-325 

5 

586 

7 

046-047 

5 

326 

4 

587 

6 

048-065 

4 

327-349 

5 

588  593 

7 

066 

3 

350-353 

4 

594 

8 

067 

4 

354-355 

5 

595 

7 

068-119 

3 

356-359 

4 

596-599 

8 

120-126 

4 

360-361 

5 

600-608 

5 

127 

3 

362 

4 

609 

4 

128-147 

4 

363  367 

5 

610-617 

5 

148-163 

3 

368 

4 

618-619 

4 

164-165  . 

4 

369  . 

5 

620  667 

5 

166-172  . 

3 

370-374 

4 

668-672 

6 

173-174  . 

2 

375 

5 

673 

5 

175-196  . 

3 

376 

3 

674  693 

6 

197-223 

2 

377-379 

4 

700-705 

5 

224  225 

.1 

380-383 

5 

706 

6 

226 

2 

384-385 

4 

707-729 

r 

227 

1 

386-397 

5 

730-742 

6 

228  229 

2 

399  410 

4 

743-744 

5 

230-232 

1 

411-412 

3 

745  748 

6 

233-237 

2 

413-414 

4 

749 

5 

238-239 

1 

415-416 

3 

750-754 

6 

240-241 

2 

417-418 

4 

755 

5 

242-243 

3 

420 

5 

756-784 

6 

244-245 

2 

421  436 

785 

7 

246-253 

3 

437  439 

3 

786-796 

6 

254 

2 

440-443 

4 

797  831 

7 

255-266 

3 

444-447 

3 

832  844 

8 

267  268 

2 

448-455 

4 

845 

7 

270-274 

3 

456-457 

3 

846  864 

8 

275-279 

2 

458-496 

4 

865  885 

7 

280-286 

3 

497-509 

5 

889  999 

8 

287-294 

4 

510-512 

6 

Chart  3  Priority  Mailing  Rates  by  Zone 


Weight. 
up  to 


f,  2,  3 

4 

5 

6 

7 

8 

2  lbs 

$2  90 

$290 

$2  90 

$2  90 

$2  90 

$2  90 

3  lbs 

4  10 

4  10 

4  10 

4  10 

4  10 

4  10 

4  lbs 

465 

4  65 

4  65 

4  65 

4  65 

4  65 

Security  Awareness  Bulletin 


38 


Number  4-92 


